Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch php php systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.
🐘 PHP PDO layer exposed! Aleksey Solovev & Nikita Sveshnikov uncovered 2 flaws: SQL Injection in pdo_firebird (CVE-2025-14179) and DoS in PDO via pdo_pgsql (CVE-2025-14180).
https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-nul-byte-sql-injection-in-pdo_firebird-and-null-pointer-dereference-in-pdo-pgsql/ https://t.co/VAhZG5FAmc
Post summary
Two newly identified vulnerabilities in PHP PDO were disclosed—a SQL injection in pdo_firebird (CVE‑2025‑14179) and a DoS via pdo_pgsql (CVE‑2025‑14180)—with an informative article linked for further details.
Two PHP PDO bugs patched in 2025-2026: CVE-2025-14179 enables SQL injection via NUL bytes in pdo_firebird, and CVE-2025-14180 causes a NULL pointer dereference crash in pdo_pgsql, both rooted in unsafe C-level input handling.
Key findings:
- CVE-2025-14179 (High) hits pdo_firebird's php_firebird_preprocess tokenizer. The quoting routine PDO::quote works correctly, but when the rebuilt SQL string passes through php_firebird_alloc_prepare_stmt, a strncat() call truncates on the first NUL byte (\0), dropping the closing quote of a string literal. Attacker input escapes the quoted context and is parsed as executable SQL. The exploit pattern: quote with PDO::quote, pass to PDO::prepare, inject \0 in the first parameter, then place a UNION SELECT payload in the second. Fixed in commit 3f40b65 by replacing strncat() with a binary-safe length-bounded copy.
- CVE-2025-14180 (Moderate, CVSS 6.3) affects pdo_pgsql when PDO::ATTR_EMULATE_PREPARES is true. A parameter containing an invalid multibyte sequence (e.g. alice\x99) causes libpq's PQescapeStringConn to set the error flag and the driver returns NULL. The PDO parser then evaluates ZSTR_LEN(NULL), dereferencing address 0x0, delivering SIGSEGV and killing the PHP worker instantly. The try/catch block never fires because the crash is at C level.
- The DoS has real financial impact. In autocommit mode, a debit UPDATE commits before the crash point, but the order INSERT, inventory UPDATE, and invoice INSERT never run.
#DFIR_Radar
Post summary
The post discloses detailed technical information about two PHP PDO bugs and provides patch details, with no evidence of active exploitation or proof‑of‑concept code.
The post lists five trending CVE identifiers without providing any additional technical context, PoC, exploit details, patches, or evidence of active exploitation.
🚨 Positive Technologies has disclosed two high-severity flaws in PHP's PDO extension: CVE-2025-14180 (CVSS 8.2), a NULL pointer dereference in pdo_pgsql that lets unauthenticated attackers crash PHP worker processes with a malformed byte sequence, and CVE-2025-14179, an SQL injection via NUL byte mishandling in the Firebird driver.
⚠️ The PostgreSQL bug only triggers when PDO::ATTR_EMULATE_PREPARES is enabled, making any input field reaching a prepared statement a potential DoS vector.
Recommended actions:
🔹 Upgrade to patched PHP releases (8.1.34, 8.2.31, 8.3.31, 8.4.21, or 8.5.6+)
🔹 Disable PDO::ATTR_EMULATE_PREPARES in PostgreSQL connections as an interim mitigation
Post summary
Positive Technologies disclosed two high‑severity PHP PDO extension flaws, CVE‑2025‑14180 and CVE‑2025‑14179, and provided remediation guidance, urging upgrades to patched PHP releases and disabling PDO::ATTR_EMULATE_PREPARES to mitigate DoS and injection risks.