CVE-2026-6104 (matched: php)

  • Saturday, 25th July, 2026
  • 10:03am

A security issue has been identified in specific versions of PHP, the software that powers most dynamic, interactive websites. It affects PHP 8.4 releases older than 8.4.21, and PHP 8.5 releases older than 8.5.6.

The flaw is triggered when a specially crafted encoding name with a hidden, embedded null character is passed to common PHP text handling functions, including tools that convert or detect character sets for your site’s content, plus related server configuration settings. A bug in how PHP checks these encoding names can cause the software to read server memory it is not supposed to access.

If exploited, this issue could cause your website to crash unexpectedly, or in rare cases leak small amounts of sensitive data stored on the server.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6104

« Back