CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-6722

Critical · CVSS 9.8

PHP SOAP extension — Use-after-free (UAF) / dangling pointer via SOAP object deduplication leading to Remote Code Execution

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-416, CWE-825

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

Search profile — drives PoC discovery

Symbols apache:Maphrefobject deduplicationSOAP extensionreference countdangling pointerfreed PHP objectglobal mapduplicate keystemporary result map
Keywords CVE-2026-6722PHP SOAP use-after-freePHP SOAP RCESOAP object deduplication UAFapache:Map duplicate keys PHPPHP SOAP href dangling pointerGHSA-85c2-q967-79q5PHP use-after-free SOAP extensionPHP 8.2 8.3 8.4 8.5 SOAP UAFCWE-416 PHP SOAP
Versions: 8.2.* < 8.2.31, 8.3.* < 8.3.31, 8.4.* < 8.4.21, 8.5.* < 8.5.6

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z