CVE-2024-2757: PHP
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
Affected products
- PHP PHP: from 8.3.0, before 8.3.5 (fixed in 8.3.5)
Published 2024-04-29. Last modified 2026-06-17.