CVE-2025-14180General(php / php)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch php php systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-06); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-06: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-07: 105-1405-1507-0607-07
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-141
General1
2026-05-151
General1
2026-07-062
Disclosure1Patch1
2026-07-071
Disclosure1
Full discourse5 posts
  • PT SWARM@ptswarm
    Disclosure

    🐘 PHP PDO layer exposed! Aleksey Solovev & Nikita Sveshnikov uncovered 2 flaws: SQL Injection in pdo_firebird (CVE-2025-14179) and DoS in PDO via pdo_pgsql (CVE-2025-14180). https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-nul-byte-sql-injection-in-pdo_firebird-and-null-pointer-dereference-in-pdo-pgsql/ https://t.co/VAhZG5FAmc

    Post summary

    Two newly identified vulnerabilities in PHP PDO were disclosed—a SQL injection in pdo_firebird (CVE‑2025‑14179) and a DoS via pdo_pgsql (CVE‑2025‑14180)—with an informative article linked for further details.

    010029113.9K
    18.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Two PHP PDO bugs patched in 2025-2026: CVE-2025-14179 enables SQL injection via NUL bytes in pdo_firebird, and CVE-2025-14180 causes a NULL pointer dereference crash in pdo_pgsql, both rooted in unsafe C-level input handling. Key findings: - CVE-2025-14179 (High) hits pdo_firebird's php_firebird_preprocess tokenizer. The quoting routine PDO::quote works correctly, but when the rebuilt SQL string passes through php_firebird_alloc_prepare_stmt, a strncat() call truncates on the first NUL byte (\0), dropping the closing quote of a string literal. Attacker input escapes the quoted context and is parsed as executable SQL. The exploit pattern: quote with PDO::quote, pass to PDO::prepare, inject \0 in the first parameter, then place a UNION SELECT payload in the second. Fixed in commit 3f40b65 by replacing strncat() with a binary-safe length-bounded copy. - CVE-2025-14180 (Moderate, CVSS 6.3) affects pdo_pgsql when PDO::ATTR_EMULATE_PREPARES is true. A parameter containing an invalid multibyte sequence (e.g. alice\x99) causes libpq's PQescapeStringConn to set the error flag and the driver returns NULL. The PDO parser then evaluates ZSTR_LEN(NULL), dereferencing address 0x0, delivering SIGSEGV and killing the PHP worker instantly. The try/catch block never fires because the crash is at C level. - The DoS has real financial impact. In autocommit mode, a debit UPDATE commits before the crash point, but the order INSERT, inventory UPDATE, and invoice INSERT never run. #DFIR_Radar

    Post summary

    The post discloses detailed technical information about two PHP PDO bugs and provides patch details, with no evidence of active exploitation or proof‑of‑concept code.

    10100255
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-44578 2 - CVE-2016-5195 3 - CVE-2026-0073 4 - CVE-2026-20841 5 - CVE-2025-14180 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing any additional technical context, PoC, exploit details, patches, or evidence of active exploitation.

    000101.6K
    1.7K followersView on X
  • TECHEPAGES@techepages
    Disclosure

    🚨 Positive Technologies has disclosed two high-severity flaws in PHP's PDO extension: CVE-2025-14180 (CVSS 8.2), a NULL pointer dereference in pdo_pgsql that lets unauthenticated attackers crash PHP worker processes with a malformed byte sequence, and CVE-2025-14179, an SQL injection via NUL byte mishandling in the Firebird driver. ⚠️ The PostgreSQL bug only triggers when PDO::ATTR_EMULATE_PREPARES is enabled, making any input field reaching a prepared statement a potential DoS vector. Recommended actions: 🔹 Upgrade to patched PHP releases (8.1.34, 8.2.31, 8.3.31, 8.4.21, or 8.5.6+) 🔹 Disable PDO::ATTR_EMULATE_PREPARES in PostgreSQL connections as an interim mitigation

    Post summary

    Positive Technologies disclosed two high‑severity PHP PDO extension flaws, CVE‑2025‑14180 and CVE‑2025‑14179, and provided remediation guidance, urging upgrades to patched PHP releases and disabling PDO::ATTR_EMULATE_PREPARES to mitigate DoS and injection risks.

    0000031
    19 followersView on X
  • LAQfrinchi@SantiagoYoan
    General

    @DamianCatanzaro Pero de que hablas, si el el 24/12/2025 hace pocos meses tambien habia caido PHP CVE-2025-14180 🤣🤣🤣🤣

    Post summary

    The tweet references a past incident with CVE-2025-14180 but gives no technical, exploit, or mitigation details.

    000001.9K
    416 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more