ID:12736 - Exploit for Memory leak in PHP - CVE-2025-14177
Published: May 22, 2026
Vulnerability identifier: #VU120272
Vulnerability risk: Medium
CVE-ID: CVE-2025-14177
CWE-ID: CWE-401
Exploitation vector: Remote access
Vulnerable software:
PHP
PHP
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in getimagesize. A remote attacker can force the application to leak memory and perform denial of service attack.
Remediation
Install updates from vendor's website.