CVE-2026-17544 (matched: php)

  • Wednesday, 5th August, 2026
  • 22:04pm

A security vulnerability has been identified in specific recent versions of PHP, the programming language that powers most dynamic, interactive websites. The flaw exists in the bccomp() function, which is used to compare high-precision decimal numbers, a feature commonly used for tasks like pricing calculations, financial tools, or inventory management on sites. The vulnerability affects PHP 8.4 releases older than version 8.4.24, and PHP 8.5 releases older than version 8.5.9. If a site runs one of these affected PHP versions, an attacker can send specially crafted input to trigger the flaw, which causes corruption of the server's memory. This type of memory corruption can lead to

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17544

« Back