CVE-2026-91767 | PHP up to 8.2.33/8.3.34/8.4.25/8.5.10 OpenSSL ext/openssl/xp_ssl.c php_openssl_matches_wildcard_name length heap-based overflow
A vulnerability has been found in PHP up to 8.2.33/8.3.34/8.4.25/8.5.10 and classified as critical. This issue affects the function php_openssl_matches_wildcard_name of the file ext/openssl/xp_ssl.c of the component OpenSSL. Performing a manipulation of the argument length results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-91767. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More