CVE-2016-5873: PHP Pecl HTTP

Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.

Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.

Affected products

  • PHP Pecl HTTP: up to and including 3.0.1

Published 2017-01-23. Last modified 2026-06-17.