MEDIUM 6.5 NVD
CVE-2025-14181
The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed t
The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller than the data it then writes into it, producing a heap buffer overflow.
Remediation
$ sudo apt install --only-upgrade php8.4References
- https://github.com/php/php-src/security/advisories/GHSA-cj93-vc83-wgqv
- https://github.com/php/php-src/security/advisories/GHSA-cj93-vc83-wgqv
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-09-25 via NVD. A remediation command is available below.
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.