CVE-2026-91767: PHP Group PHP
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.
Affected products
- PHP Group PHP: from 8.2, before 8.2.34 (fixed in 8.2.34); from 8.3, before 8.3.35 (fixed in 8.3.35); from 8.4, before 8.4.26 (fixed in 8.4.26); from 8.5, before 8.5.11 (fixed in 8.5.11)
Published 2026-09-25. Last modified 2026-09-29.