CVE-2025-1735

MEDIUM

PHP 8.1.0-8.1.32 - Denial of Service via PostgreSQL Escaping Function Error Handling

Title source: llm
STIX 2.1

Description

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.

Scores

CVSS v3 5.9
EPSS 0.0059
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476 CWE-89
Status published
Products (1)
php/php 8.1.0 - 8.1.33
Published Jul 13, 2025
Tracked Since Feb 18, 2026