CVE-2026-7259Patch(php / php)

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch php php systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 4
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline10 mentions / 3d
01234Mentions · 2026-05-10: 2Mentions · 2026-05-12: 4Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-12: 4Patch / Workaround · 2026-05-13: 4Technical Details · 2026-05-10: 205-1005-1205-13
Signal classification2 categories
Patch
880.0%
Disclosure
220.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure2
2026-05-124
Patch4
2026-05-134
Patch4
Full discourse10 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1 https://kusanagi.tokyo/en/releases/24567/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    The release announces a patch update for the kusanagi-php83 module that addresses several CVEs, but it offers no technical or exploit details.

    010101.1K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    An update to KUSANAGI PHP 8.3.31-1 is released, patching multiple CVEs, without any discussion of PoC, exploit, or active malicious use.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1.el9 https://kusanagi.tokyo/releases/24559/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    KUSANAGI 9 modules were updated to address multiple CVEs, indicating a patch release without additional exploit or PoC details.

    0101099
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1.el9 https://kusanagi.tokyo/releases/24522/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    An update to kusanagi-php82 (8.2.31‑1.el9) is released, claiming to patch multiple CVEs.

    0101094
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1.el9 https://kusanagi.tokyo/en/releases/24560/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    The Kusanagi-php83 update 8.3.31‑1.el9 introduces patches for several CVEs, addressing security vulnerabilities in the PHP module.

    000001.0K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1 https://kusanagi.tokyo/en/releases/24534/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    KUSANAGI released an update for its PHP modules, addressing multiple CVEs by upgrading to newer versions. The advisory mentions the patch but provides no PoC, exploit detail, or exploitation evidence.

    00000787
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1 https://kusanagi.tokyo/releases/24533/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    The post announces a PHP module update that includes fixes for several CVEs, indicating a patch release rather than a PoC or exploit announcement.

    0000070
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1.el9 https://kusanagi.tokyo/en/releases/24523/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    The KUSANAGI 9 module update 8.2.31-1.el9 delivers patches for several listed CVEs, addressing the mentioned vulnerabilities.

    00000753
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7259 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to … https://www.cve.org/CVERecord?id=CVE-2026-7259

    Post summary

    The text announces CVE‑2026‑7259, describing affected PHP versions and a technical mismatch, but offers no PoC, exploit, or remediation details.

    00000137
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7259 Denial of Service via NULL Pointer Dereference in PHP Multibyte Regex Encoding https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7259

    Post summary

    A new denial‑of‑service vulnerability (CVE‑2026‑7259) affecting PHP’s multibyte regex engine has been announced, with a brief technical description and a link to more details.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more