CVE-2026-91765

NameCVE-2026-91765
Descriptioncleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6514-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php8.2 (PTS)bookworm8.2.32-1~deb12u1vulnerable
bookworm (security)8.2.33-1~deb12u1vulnerable
php8.4 (PTS)trixie8.4.24-1~deb13u1vulnerable
trixie (security)8.4.26-1~deb13u1fixed
forky, sid8.4.24-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php8.2source(unstable)(unfixed)
php8.4sourcetrixie8.4.26-1~deb13u1DSA-6514-1
php8.4source(unstable)(unfixed)

Notes

https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm
https://github.com/php/php-src/blob/php-8.4.26/NEWS

Search for package or bug name: Reporting problems