CVE-2025-6491

MEDIUM

PHP 8.1.0-8.1.32 - Null Pointer Dereference in SOAP XML Namespace Prefix Parsing

Title source: llm
STIX 2.1

Description

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

Scores

CVSS v3 5.9
EPSS 0.0077
EPSS Percentile 73.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
php/php 8.1.0 - 8.1.33
Published Jul 13, 2025
Tracked Since Feb 18, 2026