debian · CVE-2026-7263

Quick triage

Priority: unimportant Published: Updated: Sat, 27 Jun 2026 15:00:49 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-7263 unimportant priority: Debian including 3 source packages (php7.4, php8.2, php8.4), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.

Description:

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

cvelogic Threat Intelligence