CVE-2026-93682: PHP Group PHP
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.
Affected products
- PHP Group PHP: from 8.2, before 8.2.34 (fixed in 8.2.34); from 8.3, before 8.3.35 (fixed in 8.3.35); from 8.4, before 8.4.26 (fixed in 8.4.26); from 8.5, before 8.5.11 (fixed in 8.5.11)
Published 2026-09-25. Last modified 2026-09-29.