EIP-2026-104672

PRE-CVE

PHP GMP - 'unserialize()' Use-After-Free

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104672. PoCs published by Taoguang Chen.

AI-analyzed exploit summary This exploit demonstrates a use-after-free vulnerability in PHP's unserialize() function with GMP objects, allowing arbitrary memory manipulation and potential remote code execution. The PoC constructs a malicious serialized string that triggers the vulnerability, enabling control over freed memory.

Description

PHP GMP - 'unserialize()' Use-After-Free

Exploits (1)

exploitdb WORKING POC
by Taoguang Chen · textdosphp
https://www.exploit-db.com/exploits/38121

This exploit demonstrates a use-after-free vulnerability in PHP's unserialize() function with GMP objects, allowing arbitrary memory manipulation and potential remote code execution. The PoC constructs a malicious serialized string that triggers the vulnerability, enabling control over freed memory.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PHP 5.6 < 5.6.13
No auth needed
Prerequisites: PHP 5.6 < 5.6.13 with GMP extension enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026