CVE-2014-8142: PHP

High severity, CVSS 7.5. EPSS: 53.2% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.

Affected products

  • PHP PHP: up to and including 5.4.35; version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; …

Published 2014-12-20. Last modified 2026-06-17.