---
cve: "CVE-2026-7263"
severity: "MEDIUM"
cvss: 6.3
epss: "35%"
vendor: "PHP Group"
kev: false
exploited: false
published: "2026-05-10 06:16:08"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T17:02:02+02:00"
---

# CVE-2026-7263

> 6.3 MEDIUM · 🧪 PoC

## Beschreibung

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/AU:Y/RE:M/U:Amber
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://github.com/php/php-src/security/advisories/GHSA-4jhr-8w89-j733>
- <https://access.redhat.com/errata/RHSA-2026:22649>
- <https://access.redhat.com/security/cve/CVE-2026-7263>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2468572>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7263.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-7263) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
