CVE-2026-7261·PHP vulnerability
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
- Severity
- critical
- Software
- PHP
- Fixed in
- 8.5.6
- Published
- 2026-05-10
Affected versions
From: 8.5.0
Until: 8.5.6
Fixed in: 8.5.6
How to fix this CVE
Update PHP to version 8.5.6 or later immediately to resolve a critical use-after-free vulnerability in the SOAP extension when session persistence is enabled. Organizations running PHP 8.2.x, 8.3.x, 8.4.x, or 8.5.x versions prior to the patched releases should prioritize this update, as the vulnerability can result in memory corruption, information leaks, or denial of service.
sudo dnf update phpDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check the installed PHP version by running: php -v
- Step 2: Verify if SOAP persistence is enabled by searching php.ini for 'session.serialize_handler' and checking SoapServer configurations in application code for 'SOAP_PERSISTENCE_SESSION'
- Step 3: Monitor Apache/Nginx access logs and PHP error logs for patterns like 'Segmentation fault', 'memory corruption', or repeated 'SOAP' request failures followed by process crashes
- Step 4: After applying updates, confirm the patched version is active by running: php -v and verify no PHP-FPM process crashes occur during SOAP request handling
FAQ
What is CVE-2026-7261?
A critical use-after-free vulnerability in PHP's SOAP extension that occurs when session persistence is enabled and SOAP requests fail, allowing attackers to trigger memory corruption or information disclosure through crafted SOAP messages.
Is CVE-2026-7261 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits have been disclosed.
What versions of PHP are affected by CVE-2026-7261?
PHP 8.2.x before 8.2.31, 8.3.x before 8.3.31, 8.4.x before 8.4.21, and 8.5.x before 8.5.6 are all affected.
How do I check if my server is vulnerable to CVE-2026-7261?
Run 'php -v' and if your version falls within the vulnerable ranges (8.2.0-8.2.30, 8.3.0-8.3.30, 8.4.0-8.4.20, or 8.5.0-8.5.5), your system is vulnerable. Additionally confirm SoapServer is loaded with 'php -m | grep soap'.
Does Defensia detect CVE-2026-7261?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP is installed on a monitored server, CVE-2026-7261 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-7261. Free for 1 server.
Get started free