Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6722

45
FAUCET Score

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

First published: May 10, 2026Last modified: May 11, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.2.0, < 8.2.31CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.3.0, < 8.3.31CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.4.0, < 8.4.21CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.5.0, < 8.5.6CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.5CRITICAL

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Red

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.89%
Probability of exploitation in next 30 days
EPSS Percentile
55.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0089 is in the 40th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: php8.1 (jammy)Fixed in: 8.1.2-1ubuntu2.24
ubuntupatch availablevia ubuntu_usn
Product: php8.3 (noble)Fixed in: 8.3.6-0ubuntu0.24.04.9
ubuntupatch availablevia ubuntu_usn
Product: php8.4 (questing)Fixed in: 8.4.11-1ubuntu1.2
ubuntupatch availablevia ubuntu_usn
Product: php8.5 (resolute)Fixed in: 8.5.4-0ubuntu1.1
ubuntupatch availablevia ubuntu_usn
Product: php7.0 (xenial)Fixed in: 7.0.33-0ubuntu0.16.04.16+esm19
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (3)

ubuntuUSN-8513-1

PHP vulnerabilities

Jul 6, 2026
ubuntuUSN-8336-1

PHP vulnerabilities

May 28, 2026
microsoft2026-May/CVE-2026-6722Critical

Use-After-Free in SOAP using Apache map

May 7, 2026

References

access.redhat.com / errata/RHSA-2026:22142
access.redhat.com / errata/RHSA-2026:22143
access.redhat.com / errata/RHSA-2026:22305
access.redhat.com / errata/RHSA-2026:22649
access.redhat.com / errata/RHSA-2026:23388
access.redhat.com / errata/RHSA-2026:33449
access.redhat.com / errata/RHSA-2026:34354
access.redhat.com / security/cve/CVE-2026-6722
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6722.json
github.com / php/php-src/security/advisories/GHSA-85c2-q967-79q5
Vendor Advisory