CVE-2025-6491 is a null pointer dereference vulnerability affecting PHP versions 8.1.*, 8.2.*, 8.3.*, and 8.4.* when processing overly large XML namespace prefixes within SOAP extensions. This flaw, rated Medium severity (CVSS 5.9), can be exploited remotely with high attack complexity, leading to server crashes and impacting availability. Currently, there is no known public exploit code, nor is it listed on the CISA KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.1.33CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.2.0, < 8.2.29CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.3.0, < 8.3.23CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.4.0, < 8.4.10CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
Jul 8, 2025php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
Jul 5, 2025