CVE-2026-17544
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
- Affected products
- Php
- Php
- < 8.4.24, 8.5.9
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2026-07-30
- Attack patterns
- CAPEC-100
CVE-2026-17544 at NVD
2 known exploits for CVE-2026-17544
Proof-of-concept code and exploit modules indexed by Sploitus