Clandestine[verified]@akaclandestineDisclosure
A researcher has disclosed two new memory-safety bugs in PHP’s ext/standard, with details available in an external article.
DFIR Radar[verified]@DFIR_RadarPoC
Researchers discovered two critical heap memory bugs in PHP’s core JPEG processing, detailed their technical aspects, and provided PoCs illustrating exploitation via php://filter streams and FIFO pipes.
UNDERCODE TESTING[verified]@UndercodeUpdateDisclosure
The post announces a new JPEG image attack targeting a critical PHP heap overflow (CVE‑2025‑14177) and includes a link to more details, but provides limited information on exploitation, patches, or PoC code.
PT SWARM@ptswarmDisclosure
A research team has disclosed two JPEG‑related memory‑safety bugs in PHP, providing technical details but no PoC, exploit code, or patch information.
Autumn Good@autumn_good_35Disclosure
The article announces the new CVE‑2025‑14177, describing JPEG‑related memory vulnerabilities in PHP and providing proof‑of‑concept details, but does not report active exploitation, patches, or debunking.
Moselwal Digitalagentur GmbH@moselwalDisclosure
The tweet announces CVE-2025-14177, a heap‑size corruption issue in PHP’s getimagesize() whose details are linked in a blog post, with no evidence of active exploitation, patches, or PoC code.