EIP-2026-104669
PRE-CVEPHP 7.0 - JsonSerializable::jsonSerialize json_encode Local Denial of Service
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104669. PoCs published by Yakir Wizman.
AI-analyzed exploit summary This PHP script demonstrates a local denial-of-service vulnerability in PHP 7.0 by exploiting recursive serialization in the JsonSerializable interface. The jsonSerialize method recursively creates instances of itself, causing json_encode to crash due to infinite recursion.
Description
PHP 7.0 - JsonSerializable::jsonSerialize json_encode Local Denial of Service
Exploits (1)
This PHP script demonstrates a local denial-of-service vulnerability in PHP 7.0 by exploiting recursive serialization in the JsonSerializable interface. The jsonSerialize method recursively creates instances of itself, causing json_encode to crash due to infinite recursion.