
CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data stru… https://www.cve.org/CVERecord?id=CVE-2026-7263
Post summary
A new PHP vulnerability (CVE-2026-7263) targets DOMNode::C14N() in PHP 8.4.* prior to 8.4.21 and 8.5.* prior to 8.5.6, potentially leading to a circular linked list when XML data is improperly processed.

