DFIR Radar[verified]@DFIR_RadarPatch
The post discloses two PHP PDO CVEs, details the exploitation mechanisms and crash behavior, and notes the specific patch commit that fixes each vulnerability.
TECHEPAGES[verified]@techepagesDisclosure
Positive Technologies disclosed two high‑severity PHP PDO extension flaws—CVE‑2025‑14180 causing crashes via NULL pointer dereference and CVE‑2025‑14179 enabling SQL injection through NUL byte mishandling—and advised upgrading PHP or disabling PDO::ATTR_EMULATE_PREPARES to mitigate attacks.
PT SWARM@ptswarmDisclosure
The post discloses two new PHP PDO layer vulnerabilities—SQL injection (CVE‑2025‑14179) and DoS (CVE‑2025‑14180)—and links to a detailed write‑up, but offers no evidence of active exploitation or available fixes.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
KUSANAGI released a PHP module update that patches multiple CVE vulnerabilities by upgrading to PHP 8.3.31‑1, with no exploits or PoCs disclosed.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
KUSANAGI 9 update to php8.3.31-1 addresses multiple CVEs, serving as a patch without mentioning PoC or exploitation details.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
KUSANAGI 9 modules were updated to version 8.3.31-1.el9, providing patches for multiple CVEs (e.g., CVE-2026-6735, CVE-2026-7259).
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The release notes announce updates that patch several listed CVEs, providing a straightforward patch announcement.
CVE@CVEnewDisclosure
The text provides a brief disclosure of a vulnerability in PHP’s PDO Firebird driver involving improper handling of NUL bytes across certain PHP versions, but offers no details on PoC, exploit code, active exploitation, or patches.