Use-after-free in PHP - CVE-2026-7261
Published: May 10, 2026
PHP
PHP Group
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in SOAP header parsing when a header parsing failure occurs with SOAP_PERSISTENCE_SESSION. A remote attacker can send a specially crafted SOAP request to cause a denial of service.
Exploitation requires SOAP_PERSISTENCE_SESSION.