CVE-2026-91765: PHP Group PHP

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

Affected products

  • PHP Group PHP: from 8.2, before 8.2.34 (fixed in 8.2.34); from 8.3, before 8.3.35 (fixed in 8.3.35); from 8.4, before 8.4.26 (fixed in 8.4.26); from 8.5, before 8.5.11 (fixed in 8.5.11)

Published 2026-09-25. Last modified 2026-09-29.