CVE-2026-7568Disclosure(php / php)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch php php systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-10: 2Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-10: 205-1005-1205-13
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure2
2026-05-121
Patch1
2026-05-131
Patch1
Full discourse4 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    The Kusanagi module update announces new versions that patch multiple listed CVEs, with no mention of PoC, exploits, or ongoing attacks.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1 https://kusanagi.tokyo/releases/24533/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    The post announces a KUSANAGI PHP module update (8.2.31‑1) that addresses multiple CVEs, without detailing exploitation or providing a PoC.

    0000070
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signe… https://www.cve.org/CVERecord?id=CVE-2026-7568

    Post summary

    CVE-2026-7568 is a disclosed PHP Metaphone function bug affecting specific minor releases, with technical details provided but no PoC, exploit, active exploitation, or patch mentioned.

    00000123
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7568 Signed Integer Overflow in PHP metaphone() Function Causes Denial of Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7568

    Post summary

    The post announces CVE-2026-7568, a signed integer overflow in PHP's metaphone() function that leads to a denial‑of‑service condition, providing a brief technical description and a link for more details.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more