{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-91767","assignerOrgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","state":"PUBLISHED","assignerShortName":"php","dateReserved":"2026-09-15T00:41:16.041Z","datePublished":"2026-09-25T20:53:42.587Z","dateUpdated":"2026-09-28T13:31:31.640Z"},"containers":{"cna":{"providerMetadata":{"orgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","shortName":"php","dateUpdated":"2026-09-25T20:53:42.587Z"},"title":"Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN","datePublic":"2026-09-25T20:49:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-122","description":"CWE-122 Heap-based buffer overflow","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-100","descriptions":[{"lang":"en","value":"CAPEC-100 Overflow Buffers"}]}],"affected":[{"vendor":"PHP Group","product":"PHP","packageName":"ext-openssl","versions":[{"status":"affected","version":"8.2.*","lessThan":"8.2.34","versionType":"semver"},{"status":"affected","version":"8.3.*","lessThan":"8.3.35","versionType":"semver"},{"status":"affected","version":"8.4.*","lessThan":"8.4.26","versionType":"semver"},{"status":"affected","version":"8.5.*","lessThan":"8.5.11","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><code>php_openssl_matches_wildcard_name()</code> in <code>ext/openssl/xp_ssl.c</code> underflows the length argument passed to <code>memchr()</code> when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to <code>SIZE_MAX</code> bytes past the end of a heap allocation. The path is reachable from any default client stream, because <code>verify_peer_name</code> is enabled by default.</p>"}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-xr7j-rvgx-xq5p","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":6.5,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}}],"credits":[{"lang":"en","value":"Mohamed Sayed  (flex0geek)","type":"reporter"},{"lang":"en","value":"Jakub Zelenka","type":"remediation developer"},{"lang":"en","value":"Arnaud Le Blanc","type":"remediation developer"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-91767","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-28T12:56:38.307648Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-28T13:31:31.640Z"}}]}}