CVE-2025-1218: PHP Group PHP

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.

Affected products

  • PHP Group PHP: from 8.2, before 8.2.34 (fixed in 8.2.34); from 8.3, before 8.3.35 (fixed in 8.3.35); from 8.4, before 8.4.26 (fixed in 8.4.26); from 8.5, before 8.5.11 (fixed in 8.5.11)

Published 2026-09-25. Last modified 2026-09-29.