CVE-2025-14177Disclosure(php / php)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-15); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
php

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-05-15: 4Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-15: 2Technical Details · 2026-05-15: 4Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 105-1505-1805-19
Signal classification2 categories
Disclosure
583.3%
PoC
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-154
Disclosure3PoC1
2026-05-181
Disclosure1
2026-05-191
Disclosure1
Full discourse6 posts
  • PT SWARM@ptswarm
    Disclosure

    🐘 PHP JPEG bugs: how image parsing leads to memory corruption. Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed. https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-jpeg-related-memory-safety-bugs-in-php/ https://t.co/JlGDFvZOxd

    Post summary

    A research team has disclosed two JPEG‑related memory‑safety bugs in PHP, providing technical details but no PoC, exploit code, or patch information.

    022075368.8K
    18.8K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    🐘 PHP JPEG bugs: how image parsing leads to memory corruption. Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed. https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-jpeg-related-memory-safety-bugs-in-php/ https://t.co/iQ9q5oKSPl

    Post summary

    A researcher has disclosed two new memory-safety bugs in PHP’s ext/standard, with details available in an external article.

    020932.8K
    62.5K followersView on X
  • DFIR Radar@DFIR_Radar
    PoC

    New research reveals two critical heap memory bugs in PHP's core JPEG processing functions. Memory disclosure in getimagesize() and buffer overflow in iptcembed() affecting millions of PHP applications worldwide. Key technical details: • CVE-2025-14177: getimagesize() memory disclosure in APP segment reading due to incorrect chunk concatenation in php_read_stream_all_chunks • Heap buffer overflow in iptcembed() caused by TOCTOU race condition - buffer sized via fstat() but reads until EOF without bounds checking • Affects PHP core ext/standard extension processing JPEG metadata (EXIF, IPTC, APP markers) • Triggers on multi-chunk reads when attacker controls stream chunk size (default 8192 bytes) • PoCs demonstrate exploitation via php://filter streams and FIFO pipes Attack methodology: • Memory disclosure: Craft JPEG with large APP1 segment spanning multiple read chunks, causing last chunk to overwrite buffer start while tail remains uninitialized • Buffer overflow: Use non-regular files (FIFOs) where st_size=0 but actual data exceeds allocated buffer size • Both require predictable chunking behavior and knowledge of default chunk sizes DFIR artifacts: • Monitor for getimagesize() calls on untrusted JPEG files with unusual APP segment sizes • Look for iptcembed() usage with non-regular file inputs or rapidly growing files • Check for heap corruption indicators in PHP error logs #DFIR_Radar

    Post summary

    Researchers discovered two critical heap memory bugs in PHP’s core JPEG processing, detailed their technical aspects, and provided PoCs illustrating exploitation via php://filter streams and FIFO pipes.

    220702.0K
    1.8K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2025-14177 Hack the Elephant One Bite at a Time: JPEG-Related Memory-Safety Bugs in PHP https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-jpeg-related-memory-safety-bugs-in-php/

    Post summary

    The article announces the new CVE‑2025‑14177, describing JPEG‑related memory vulnerabilities in PHP and providing proof‑of‑concept details, but does not report active exploitation, patches, or debunking.

    000022.0K
    6.9K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 New JPEG Image Attack Exposes Critical PHP Memory Bugs: #CVE-2025-14177 & iptcembed Heap Overflow + Video https://undercodetesting.com/new-jpeg-image-attack-exposes-critical-php-memory-bugs-cve-2025-14177-iptcembed-heap-overflow-video/ Educational Purposes!

    Post summary

    The post announces a new JPEG image attack targeting a critical PHP heap overflow (CVE‑2025‑14177) and includes a link to more details, but provides limited information on exploitation, patches, or PoC code.

    000101.4K
    577 followersView on X
  • Moselwal Digitalagentur GmbH@moselwal
    Disclosure

    PHP CVE-2025-14177: getimagesize() blutet Heap-Speicher, iptcembed() bleibt offen https://moselwal.de/blog/php-getimagesize-iptcembed-cve-2025-14177 https://t.co/iIDAZopzPa

    Post summary

    The tweet announces CVE-2025-14177, a heap‑size corruption issue in PHP’s getimagesize() whose details are linked in a blog post, with no evidence of active exploitation, patches, or PoC code.

    000001.2K
    161 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---
Appphpphp8.5.0--

Explore more