CVE-2026-17544 (matched: php)

  • Thursday, 6th August, 2026
  • 16:05pm

A security flaw has been found in specific versions of PHP, the software that powers many interactive, dynamic websites. The issue impacts PHP 8.4 releases older than 8.4.24, and PHP 8.5 releases older than 8.5.9.

The flaw is triggered when an attacker sends specially crafted input to the bccomp() function on a site running an affected PHP version. This can cause out-of-bounds memory writes that corrupt server memory, which may lead to site crashes, broken functionality, or in some cases, allow attackers to access sensitive site data or take unauthorized actions on your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17544

« Back