Out-of-bounds read in PHP - CVE-2026-93682
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose limited information.
The vulnerability exists due to an out-of-bounds read in the HTTP stream wrapper redirect handling when processing a redirect response with an empty Location header. A remote attacker can operate a server that a PHP application fetches from, or redirect a request to such a server, to disclose limited information.
At most one bit, indicating whether the out-of-bounds byte is zero, is observable through the request path received by the server.