CVE-2026-91765
Public on 2026-09-25
Modified on 2026-09-25
Description
cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | php | Pending Fix | ||
| Amazon Linux 2 - Php8.2 Extra | php | Pending Fix | ||
| Amazon Linux 2 - Lamp-mariadb10.2-php7.2 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php7.1 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php7.2 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php7.3 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php7.4 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php8.0 Extra | php | No Fix Planned | ||
| Amazon Linux 2 - Php8.1 Extra | php | No Fix Planned | ||
| Amazon Linux 2023 | php8.1 | No Fix Planned | ||
| Amazon Linux 2023 | php8.2 | Pending Fix | ||
| Amazon Linux 2023 | php8.2-pecl-apcu | Not Affected | ||
| Amazon Linux 2023 | php8.2-pecl-igbinary | Not Affected | ||
| Amazon Linux 2023 | php8.2-pecl-memcached | Not Affected | ||
| Amazon Linux 2023 | php8.2-pecl-msgpack | Not Affected | ||
| Amazon Linux 2023 | php8.2-pecl-redis6 | Not Affected | ||
| Amazon Linux 2023 | php8.3 | Pending Fix | ||
| Amazon Linux 2023 | php8.4 | Pending Fix | ||
| Amazon Linux 2023 | php8.4-pecl-apcu | Not Affected | ||
| Amazon Linux 2023 | php8.4-pecl-igbinary | Not Affected | ||
| Amazon Linux 2023 | php8.4-pecl-memcached | Not Affected | ||
| Amazon Linux 2023 | php8.4-pecl-msgpack | Not Affected | ||
| Amazon Linux 2023 | php8.4-pecl-redis6 | Not Affected | ||
| Amazon Linux 2023 | php8.5 | Pending Fix | ||
| Amazon Linux 2027 Preview | php8.5 | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |