CVE-2016-5773: PHP

Critical severity, CVSS 9.8. EPSS: 9.3% chance of exploitation in the next 30 days.

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

Affected products

  • PHP PHP: up to and including 5.5.36; version 5.6.0 only; version 5.6.1 only; version 5.6.2 only; version 5.6.3 only; version 5.6.4 only; …

Published 2016-08-07. Last modified 2026-06-17.