Improper Encoding or Escaping of Output in PHP - CVE-2026-7263

 

Improper Encoding or Escaping of Output in PHP - CVE-2026-7263

Published: May 10, 2026


Vulnerability identifier: #VU130908
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-7263
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause incorrect XML canonicalization output.

The vulnerability exists due to improper handling of namespace declarations in Dom\XMLDocument::C14N() when processing XML after setAttributeNS(). A remote attacker can supply crafted XML content to cause incorrect XML canonicalization output.


Affected software

PHP
Debian Linux
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
SecurityCenter
php8.1 (Ubuntu package)
php8.4 (Debian package)
php8-fileinfo-debuginfo
php8-ftp-debuginfo
php8-enchant
php8-bz2
php8-curl-debuginfo
php8-cli
php8-ffi
php8-posix
php8-fpm-debugsource
php8-embed
php8-exif
php8-pcntl-debuginfo
php8-gd-debuginfo
php8-sysvshm
php8-pdo
php8-bcmath-debuginfo
php8-xmlreader
php8-calendar-debuginfo
php8-enchant-debuginfo
php8-ldap
php8-curl
php8-fileinfo
php8-openssl-debuginfo
php8-fpm-debuginfo
php8-zip-debuginfo
php8-fastcgi-debugsource
php8-devel
php8-pgsql
php8-mbstring-debuginfo
php8-xmlreader-debuginfo
php8-gd
php8
apache2-mod_php8-debugsource
php8-snmp-debuginfo
php8-exif-debuginfo
php8-tokenizer
php8-cli-debuginfo
php8-tidy
php8-soap
php8-fpm-apache
php8-calendar
php8-debuginfo
php8-posix-debuginfo
php8-opcache
php8-fpm
php8-dom-debuginfo
php8-zlib
apache2-mod_php8-debuginfo
php8-pgsql-debuginfo
php8-sysvsem-debuginfo
php8-ctype
php8-intl-debuginfo
php8-tokenizer-debuginfo
php8-gettext
php8-zip
php8-phar-debuginfo
php8-openssl
php8-sysvmsg
php8-sqlite
php8-embed-debugsource
php8-sodium
php8-embed-debuginfo
apache2-mod_php8
php8-xmlwriter
php8-fastcgi
php8-shmop
php8-pcntl
php8-ldap-debuginfo
php8-bcmath
php8-bz2-debuginfo
php8-xsl-debuginfo
php8-gmp-debuginfo
php8-snmp
php8-tidy-debuginfo
php8-sodium-debuginfo
php8-mysql-debuginfo
php8-readline-debuginfo
php8-soap-debuginfo
php8-sockets-debuginfo
php8-ctype-debuginfo
php8-fastcgi-debuginfo
php8-debugsource
php8-readline
php8-sysvsem
php8-odbc-debuginfo
php8-iconv-debuginfo
php8-ftp
php8-dom
php8-pdo-debuginfo
php8-gmp
php8-sockets
php8-shmop-debuginfo
php8-mysql
php8-xsl
php8-mbstring
php8-ffi-debuginfo
php8-dba-debuginfo
php8-odbc
php8-sysvmsg-debuginfo
php8-sysvshm-debuginfo
php8-sqlite-debuginfo
php8-intl
php8-zlib-debuginfo
php8-phar
php8-opcache-debuginfo
php8-iconv
php8-gettext-debuginfo
php8-dba
php8-xmlwriter-debuginfo

How to mitigate CVE-2026-7263

Install security update from vendor's website.

PHP - addressed in versions 8.4.21, 8.5.6
SecurityCenter - addressed in versions SC202607.1, SC202607.2
php8.1 (Ubuntu package) - addressed in versions 8.1.2-1ubuntu2.24, 8.3.6-0ubuntu0.24.04.9, 8.4.11-1ubuntu1.2, 8.5.4-0ubuntu1.1
php8.4 (Debian package) - update to 8.4.21-1~deb13u1
php8-fileinfo-debuginfo - update to 8.4.21-160000.1.1
php8-ftp-debuginfo - update to 8.4.21-160000.1.1
php8-enchant - update to 8.4.21-160000.1.1
php8-bz2 - update to 8.4.21-160000.1.1
php8-curl-debuginfo - update to 8.4.21-160000.1.1
php8-cli - update to 8.4.21-160000.1.1
php8-ffi - update to 8.4.21-160000.1.1
php8-posix - update to 8.4.21-160000.1.1
php8-fpm-debugsource - update to 8.4.21-160000.1.1
php8-embed - update to 8.4.21-160000.1.1
php8-exif - update to 8.4.21-160000.1.1
php8-pcntl-debuginfo - update to 8.4.21-160000.1.1
php8-gd-debuginfo - update to 8.4.21-160000.1.1
php8-sysvshm - update to 8.4.21-160000.1.1
php8-pdo - update to 8.4.21-160000.1.1
php8-bcmath-debuginfo - update to 8.4.21-160000.1.1
php8-xmlreader - update to 8.4.21-160000.1.1
php8-calendar-debuginfo - update to 8.4.21-160000.1.1
php8-enchant-debuginfo - update to 8.4.21-160000.1.1
php8-ldap - update to 8.4.21-160000.1.1
php8-curl - update to 8.4.21-160000.1.1
php8-fileinfo - update to 8.4.21-160000.1.1
php8-openssl-debuginfo - update to 8.4.21-160000.1.1
php8-fpm-debuginfo - update to 8.4.21-160000.1.1
php8-zip-debuginfo - update to 8.4.21-160000.1.1
php8-fastcgi-debugsource - update to 8.4.21-160000.1.1
php8-devel - update to 8.4.21-160000.1.1
php8-pgsql - update to 8.4.21-160000.1.1
php8-mbstring-debuginfo - update to 8.4.21-160000.1.1
php8-xmlreader-debuginfo - update to 8.4.21-160000.1.1
php8-gd - update to 8.4.21-160000.1.1
php8 - update to 8.4.21-160000.1.1
apache2-mod_php8-debugsource - update to 8.4.21-160000.1.1
php8-snmp-debuginfo - update to 8.4.21-160000.1.1
php8-exif-debuginfo - update to 8.4.21-160000.1.1
php8-tokenizer - update to 8.4.21-160000.1.1
php8-cli-debuginfo - update to 8.4.21-160000.1.1
php8-tidy - update to 8.4.21-160000.1.1
php8-soap - update to 8.4.21-160000.1.1
php8-fpm-apache - update to 8.4.21-160000.1.1
php8-calendar - update to 8.4.21-160000.1.1
php8-debuginfo - update to 8.4.21-160000.1.1
php8-posix-debuginfo - update to 8.4.21-160000.1.1
php8-opcache - update to 8.4.21-160000.1.1
php8-fpm - update to 8.4.21-160000.1.1
php8-dom-debuginfo - update to 8.4.21-160000.1.1
php8-zlib - update to 8.4.21-160000.1.1
apache2-mod_php8-debuginfo - update to 8.4.21-160000.1.1
php8-pgsql-debuginfo - update to 8.4.21-160000.1.1
php8-sysvsem-debuginfo - update to 8.4.21-160000.1.1
php8-ctype - update to 8.4.21-160000.1.1
php8-intl-debuginfo - update to 8.4.21-160000.1.1
php8-tokenizer-debuginfo - update to 8.4.21-160000.1.1
php8-gettext - update to 8.4.21-160000.1.1
php8-zip - update to 8.4.21-160000.1.1
php8-phar-debuginfo - update to 8.4.21-160000.1.1
php8-openssl - update to 8.4.21-160000.1.1
php8-sysvmsg - update to 8.4.21-160000.1.1
php8-sqlite - update to 8.4.21-160000.1.1
php8-embed-debugsource - update to 8.4.21-160000.1.1
php8-sodium - update to 8.4.21-160000.1.1
php8-embed-debuginfo - update to 8.4.21-160000.1.1
apache2-mod_php8 - update to 8.4.21-160000.1.1
php8-xmlwriter - update to 8.4.21-160000.1.1
php8-fastcgi - update to 8.4.21-160000.1.1
php8-shmop - update to 8.4.21-160000.1.1
php8-pcntl - update to 8.4.21-160000.1.1
php8-ldap-debuginfo - update to 8.4.21-160000.1.1
php8-bcmath - update to 8.4.21-160000.1.1
php8-bz2-debuginfo - update to 8.4.21-160000.1.1
php8-xsl-debuginfo - update to 8.4.21-160000.1.1
php8-gmp-debuginfo - update to 8.4.21-160000.1.1
php8-snmp - update to 8.4.21-160000.1.1
php8-tidy-debuginfo - update to 8.4.21-160000.1.1
php8-sodium-debuginfo - update to 8.4.21-160000.1.1
php8-mysql-debuginfo - update to 8.4.21-160000.1.1
php8-readline-debuginfo - update to 8.4.21-160000.1.1
php8-soap-debuginfo - update to 8.4.21-160000.1.1
php8-sockets-debuginfo - update to 8.4.21-160000.1.1
php8-ctype-debuginfo - update to 8.4.21-160000.1.1
php8-fastcgi-debuginfo - update to 8.4.21-160000.1.1
php8-debugsource - update to 8.4.21-160000.1.1
php8-readline - update to 8.4.21-160000.1.1
php8-sysvsem - update to 8.4.21-160000.1.1
php8-odbc-debuginfo - update to 8.4.21-160000.1.1
php8-iconv-debuginfo - update to 8.4.21-160000.1.1
php8-ftp - update to 8.4.21-160000.1.1
php8-dom - update to 8.4.21-160000.1.1
php8-pdo-debuginfo - update to 8.4.21-160000.1.1
php8-gmp - update to 8.4.21-160000.1.1
php8-sockets - update to 8.4.21-160000.1.1
php8-shmop-debuginfo - update to 8.4.21-160000.1.1
php8-mysql - update to 8.4.21-160000.1.1
php8-xsl - update to 8.4.21-160000.1.1
php8-mbstring - update to 8.4.21-160000.1.1
php8-ffi-debuginfo - update to 8.4.21-160000.1.1
php8-dba-debuginfo - update to 8.4.21-160000.1.1
php8-odbc - update to 8.4.21-160000.1.1
php8-sysvmsg-debuginfo - update to 8.4.21-160000.1.1
php8-sysvshm-debuginfo - update to 8.4.21-160000.1.1
php8-sqlite-debuginfo - update to 8.4.21-160000.1.1
php8-intl - update to 8.4.21-160000.1.1
php8-zlib-debuginfo - update to 8.4.21-160000.1.1
php8-phar - update to 8.4.21-160000.1.1
php8-opcache-debuginfo - update to 8.4.21-160000.1.1
php8-iconv - update to 8.4.21-160000.1.1
php8-gettext-debuginfo - update to 8.4.21-160000.1.1
php8-dba - update to 8.4.21-160000.1.1
php8-xmlwriter-debuginfo - update to 8.4.21-160000.1.1

External References

Related Security Bulletins