CVE-2025-14179Patch(php / php)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch php php systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-12); latest day: 1
  • 13 total mentions across 5 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline13 mentions / 5d
01234Mentions · 2026-05-10: 2Mentions · 2026-05-12: 4Mentions · 2026-05-13: 4Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-06: 1Patch / Workaround · 2026-05-12: 4Patch / Workaround · 2026-05-13: 4Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-13: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-07: 105-1005-1205-1307-0607-07
Signal classification2 categories
Patch
969.2%
Disclosure
430.8%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure2
2026-05-124
Patch4
2026-05-134
Patch4
2026-07-062
Disclosure1Patch1
2026-07-071
Disclosure1
Full discourse13 posts
  • PT SWARM@ptswarm
    Disclosure

    🐘 PHP PDO layer exposed! Aleksey Solovev & Nikita Sveshnikov uncovered 2 flaws: SQL Injection in pdo_firebird (CVE-2025-14179) and DoS in PDO via pdo_pgsql (CVE-2025-14180). https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-nul-byte-sql-injection-in-pdo_firebird-and-null-pointer-dereference-in-pdo-pgsql/ https://t.co/VAhZG5FAmc

    Post summary

    The post discloses two new PHP PDO layer vulnerabilities—SQL injection (CVE‑2025‑14179) and DoS (CVE‑2025‑14180)—and links to a detailed write‑up, but offers no evidence of active exploitation or available fixes.

    010029113.9K
    18.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Two PHP PDO bugs patched in 2025-2026: CVE-2025-14179 enables SQL injection via NUL bytes in pdo_firebird, and CVE-2025-14180 causes a NULL pointer dereference crash in pdo_pgsql, both rooted in unsafe C-level input handling. Key findings: - CVE-2025-14179 (High) hits pdo_firebird's php_firebird_preprocess tokenizer. The quoting routine PDO::quote works correctly, but when the rebuilt SQL string passes through php_firebird_alloc_prepare_stmt, a strncat() call truncates on the first NUL byte (\0), dropping the closing quote of a string literal. Attacker input escapes the quoted context and is parsed as executable SQL. The exploit pattern: quote with PDO::quote, pass to PDO::prepare, inject \0 in the first parameter, then place a UNION SELECT payload in the second. Fixed in commit 3f40b65 by replacing strncat() with a binary-safe length-bounded copy. - CVE-2025-14180 (Moderate, CVSS 6.3) affects pdo_pgsql when PDO::ATTR_EMULATE_PREPARES is true. A parameter containing an invalid multibyte sequence (e.g. alice\x99) causes libpq's PQescapeStringConn to set the error flag and the driver returns NULL. The PDO parser then evaluates ZSTR_LEN(NULL), dereferencing address 0x0, delivering SIGSEGV and killing the PHP worker instantly. The try/catch block never fires because the crash is at C level. - The DoS has real financial impact. In autocommit mode, a debit UPDATE commits before the crash point, but the order INSERT, inventory UPDATE, and invoice INSERT never run. #DFIR_Radar

    Post summary

    The post discloses two PHP PDO CVEs, details the exploitation mechanisms and crash behavior, and notes the specific patch commit that fixes each vulnerability.

    10100255
    1.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1 https://kusanagi.tokyo/en/releases/24567/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    KUSANAGI released a PHP module update that patches multiple CVE vulnerabilities by upgrading to PHP 8.3.31‑1, with no exploits or PoCs disclosed.

    010101.1K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    KUSANAGI 9 update to php8.3.31-1 addresses multiple CVEs, serving as a patch without mentioning PoC or exploitation details.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1.el9 https://kusanagi.tokyo/releases/24559/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    KUSANAGI 9 modules were updated to version 8.3.31-1.el9, providing patches for multiple CVEs (e.g., CVE-2026-6735, CVE-2026-7259).

    0101099
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1.el9 https://kusanagi.tokyo/releases/24522/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    The release notes announce updates that patch several listed CVEs, providing a straightforward patch announcement.

    0101094
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when prepa… https://www.cve.org/CVERecord?id=CVE-2025-14179

    Post summary

    The text provides a brief disclosure of a vulnerability in PHP’s PDO Firebird driver involving improper handling of NUL bytes across certain PHP versions, but offers no details on PoC, exploit code, active exploitation, or patches.

    00010799
    57.5K followersView on X
  • TECHEPAGES@techepages
    Disclosure

    🚨 Positive Technologies has disclosed two high-severity flaws in PHP's PDO extension: CVE-2025-14180 (CVSS 8.2), a NULL pointer dereference in pdo_pgsql that lets unauthenticated attackers crash PHP worker processes with a malformed byte sequence, and CVE-2025-14179, an SQL injection via NUL byte mishandling in the Firebird driver. ⚠️ The PostgreSQL bug only triggers when PDO::ATTR_EMULATE_PREPARES is enabled, making any input field reaching a prepared statement a potential DoS vector. Recommended actions: 🔹 Upgrade to patched PHP releases (8.1.34, 8.2.31, 8.3.31, 8.4.21, or 8.5.6+) 🔹 Disable PDO::ATTR_EMULATE_PREPARES in PostgreSQL connections as an interim mitigation

    Post summary

    Positive Technologies disclosed two high‑severity PHP PDO extension flaws—CVE‑2025‑14180 causing crashes via NULL pointer dereference and CVE‑2025‑14179 enabling SQL injection through NUL byte mishandling—and advised upgrading PHP or disabling PDO::ATTR_EMULATE_PREPARES to mitigate attacks.

    0000031
    19 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1.el9 https://kusanagi.tokyo/en/releases/24560/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    The Kusanagi PHP module release 8.3.31-1.el9 delivers patches for several listed CVEs, with no indication of exploitation, PoC, or false‑positive status.

    000001.0K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1 https://kusanagi.tokyo/en/releases/24534/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    KUSANAGI 9 updates its PHP 8.2.31-1 module to address several CVEs, with no exploitation details or PoC provided.

    00000787
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1 https://kusanagi.tokyo/releases/24533/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    KUSANAGI 9 modules, including php 8.2.31-1, have been updated to patch several listed CVEs.

    0000070
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1.el9 https://kusanagi.tokyo/en/releases/24523/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    The KUSANAGI PHP module update 8.2.31-1.el9 is announced to patch multiple CVEs (CVE‑2026‑6735, CVE‑2026‑7259, CVE‑2025‑14179, CVE‑2026‑6722), with no evidence of exploits or active attacks.

    00000753
    200 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14179 SQL Injection in PHP PDO Firebird Driver via NUL Byte Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14179

    Post summary

    The post discloses a SQL injection flaw in the PHP PDO Firebird driver caused by NUL byte handling, but provides no proof of exploitation or remediation details.

    00000782
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more