Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31627

31
FAUCET Score

CVE-2022-31627 is a critical heap corruption vulnerability affecting PHP versions 8.1.x below 8.1.8, specifically within fileinfo functions like finfo_buffer. This flaw stems from an incorrect patch to the underlying libmagic library, leading to improper memory deallocation. With a CVSS score of 9.8 (CRITICAL), it can be exploited remotely without user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. While no active exploitation, Metasploit modules, or ExploitDB entries are currently reported, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.1.0, < 8.1.8CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.02%
Probability of exploitation in next 30 days
EPSS Percentile
78.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0202 is in the 68th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

githubpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 20029-17084Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: 17719-17084Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: azl3 php 8.3.8-1 on Azure Linux 3.0Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: azl3 php 8.1.22-2 on Azure Linux 3.0Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 8.3.8-1

Vendor Advisories (4)

microsoft2024-Sep/CVE-2022-31627

CVE-2022-31627

Sep 10, 2024
githubllm-github-0b56c1c54ae2e651HIGH

AS-2023-008: PHP 8.1

Jun 7, 2023
microsoft2022-Jul/CVE-2022-31627Critical

Heap buffer overflow in finfo_buffer

Jul 12, 2022
redhatCVE-2022-31627Low

php: heap buffer overflow in finfo_buffer

Jul 8, 2022

References

bugs.php.net / bug.php
ExploitIssue TrackingPatchThird Party Advisory
security.gentoo.org / glsa/202209-20
Third Party Advisory
security.netapp.com / advisory/ntap-20220826-0008
Third Party Advisory