CVE-2025-14178

Public on 2025-12-21
Modified on 2025-12-21
Description
NOTE: https://github.com/php/php-src/security/advisories/GHSA-h96m-rvf9-jgm2
NOTE: Fixed by: https://github.com/php/php-src/commit/e6d7d34c1ae46281993036189e3bcb6528911ce8 (php-8.4.16)
DEBIANBUG: [1123574]
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Php8.1 Extra php Pending Fix
Amazon Linux 2 - Php8.2 Extra php Pending Fix
Amazon Linux 2 - Core php Not Affected
Amazon Linux 2023 php8.1 2026-01-07 ALAS2023-2025-1355 Fixed
Amazon Linux 2023 php8.2 2026-01-07 ALAS2023-2025-1354 Fixed
Amazon Linux 2023 php8.3 2026-01-07 ALAS2023-2025-1353 Fixed
Amazon Linux 2023 php8.4 2026-01-07 ALAS2023-2025-1352 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H