Threat reportVulnerabilityTL-2026-1782

Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)

highACTIVE

Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52) (TL-2026-1782), also tracked as GovCERT.HK A26-07-52, is a high-severity software vulnerability scored CVSS 8.1, first published 2026-07-31. It has no confirmed attribution, affects PHP Group PHP (ext-phar extension), references 4 CVEs (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543), maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1068), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
8.1/10High
CVEs
4Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1782

Threat ID
TL-2026-1782
Also known as
GovCERT.HK A26-07-52
Severity
HIGH
CVSS
8.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, technology, financial-services, ecommerce, health, education
Target regions
hong kong, Global
Detection rules
9
Indicators of compromise
23

How Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52) works

PHP shipped coordinated security releases (8.2.33, 8.3.33, 8.4.24, 8.5.9, all dated 2026-07-30) fixing four vulnerabilities: a Phar circular-symlink stack-exhaustion crash, a bundled-libgd GIF LZW decompression memory-corruption bug, a PostgreSQL extension SQL-injection flaw via backslash escape-string breakout, and a BCMath bccomp() out-of-bounds write. GovCERT.HK Alert A26-07-52 rates the combined impact as denial of service and tampering; NVD scores two of the four CVEs 8.1/10 (CVSS v4, HIGH), and none currently appear in the CISA KEV catalog.

On 2026-07-28 the PHP project committed fixes for four independently-discovered vulnerabilities to php-src master and all four supported release branches within a roughly three-hour window; the fixes shipped publicly on 2026-07-30 as PHP 8.5.9, 8.4.24, 8.3.33, and 8.2.33. GovCERT.HK published Security Alert A26-07-52 on 2026-07-31 summarizing the release without individual CVE technical detail, stating only that exploitation "could lead to denial of service or tampering."

1) CVE-2026-7260 (Phar, CWE-121/CWE-400/CWE-674, CVSS 5.4 v4, GHSA-vc5h-9ppw-p5f3): phar_get_link_source() in ext/phar/util.c recursively resolves symbolic links inside phar (PHP Archive) files with no depth limit or cycle detection. A crafted tar-based .phar archive containing mutually-referencing symlinks (file_a -> file_b -> file_a) drives unbounded recursion when content is retrieved (e.g. via Phar::getContent()), exhausting the C call stack and crashing the PHP process. The same release also fixed inconsistent handling of the magic ".phar" directory (paths merely starting with ".phar" vs the true magic path) across file/directory creation, copy, ArrayAccess, stream lookup, iteration, and extraction. Credited to Calvin Young (eWalker Consulting) and Enoch Chow (Isomorph Cyber).

2) CVE-2026-9672 (bundled libgd/GD extension, GIF decoder): a patch authored by Pierre Joye and committed by Ilija Tovilo on 2026-07-28 fixed ext/gd/libgd/gd_gif_in.c's LWZReadByte_() LZW-decompression routine. The code incorrectly executed `sd->table[0][i] = sd->table[1][0] = 0;` instead of `sd->table[0][i] = sd->table[1][i] = 0;` when initializing the GIF LZW code table, and was missing a bounds-check return path (an added `return -2;`). A maliciously crafted GIF image processed by the GD extension (e.g. an attacker-supplied image upload later thumbnailed/re-encoded by a web application) can corrupt the LZW table state, leading to memory corruption during decode. NVD had not yet published a CVSS score/CWE for this CVE at analysis time ("Awaiting Analysis"); given the memory-safety class of the bug (analogous to historical GD/GdkPixbuf GIF LZW flaws such as CVE-2021-44648), it is assessed here as at least a denial-of-service risk with unconfirmed code-execution potential pending a full NVD writeup.

3) CVE-2026-17543 (pgsql extension, CWE-89, CVSS 8.1 v4 HIGH, GHSA-7qpv-r5mr-78m4): php_pgsql_convert() in ext/pgsql/pgsql.c (~lines 4751-4757), used by pg_insert(), pg_update(), pg_select(), and pg_delete(), wraps escaped values in PostgreSQL escape-string constants (E'...') using PQescapeStringConn(). PQescapeStringConn() does not escape backslashes when the server has standard_conforming_strings = on -- the PostgreSQL default since version 9.1 -- allowing an attacker-controlled value ending in a backslash to prematurely terminate the E'...' literal and inject arbitrary SQL. Published PoC: `pg_select($db, 'user', ['name' => "zzz\\' OR 1=1 --"])` renders as `SELECT * FROM "user" WHERE "name"='zzz\'' OR 1=1 --';`, returning all rows. The fix switches php_pgsql_convert() to use non-escaping string constants so backslash breakout is no longer possible. Reported by ExPatch-LLC; fix by iluuu1994, reviewed by mbeccati, analysis by alexandre-daubois.

4) CVE-2026-17544 (bcmath extension, CWE-121/CWE-787, CVSS 8.1 v4 HIGH, GHSA-x692-q9x7-8c3f): bc_str2num() in ext/bcmath/libbcmath/src/str2num.c mishandles trailing-zero truncation when a caller-specified scale shortens a numeric string. The code adjusts str_scale (`str_scale -= fractional_end - fractional_new_end;`) but fails to also adjust fractional_end, so bc_copy_and_toggle_bcd() subsequently copies BCD data past the shortened allocation -- an out-of-bounds write reachable via bccomp() with attacker-controlled operand and scale, corrupting stack or heap memory depending on whether BCMath's arena allocator or a heap fallback backs the buffer. Reported by recepasan; analysis by iluuu1994. Only PHP 8.4.x (before 8.4.24) and 8.5.x (before 8.5.9) are affected per the GHSA advisory.

All four fixes are cumulative across the affected branches; administrators running any PHP branch prior to the patched point releases should upgrade. None of the four CVEs are present in the CISA KEV catalog (1,656 entries as of 2026-07-29) and no public reports of in-the-wild exploitation were identified, consistent with GovCERT.HK's decision not to flag this as a High Threat alert.

Direct NVD verification confirms CVE-2026-7260's actual severity is materially lower than the other three: CVSS v3.1 5.5 (MODERATE), vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, and CVSS v4.0 5.4 (MEDIUM), vector AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H -- both scorings mark the attack vector Local (not Network) and require user interaction, consistent with the Phar bug only being reachable when an application or administrator actively opens/extracts an attacker-supplied .phar archive rather than being remotely triggerable like the pgsql and BCMath issues. CVE-2026-17543 and CVE-2026-17544 both independently confirm CVSS v4.0 8.1 (HIGH), Network attack vector, no privileges/no user interaction required. All four CVE records carried NVD 'Awaiting Analysis' status as of 2026-07-31, and CVE-2026-9672 (libgd) still had no published NVD CVSS/CWE record at analysis time.

The same PHP 8.5.9 / 8.4.24 point releases that carry these four fixes also bundle patches for several unrelated vulnerabilities per the official PHP ChangeLog -- OpenSSL AES-WRAP-PAD memory corruption (CVE-2026-14355), an MBString mb_ereg_search_init() NULL pointer dereference (CVE-2026-7259), a DOM duplicate-xmlns-declaration issue (CVE-2026-7263), and a Standard-extension signed integer overflow (CVE-2026-7568) -- confirming this was part of PHP's routine broader coordinated security-release cadence rather than an emergency single-issue patch; those four CVEs are outside GovCERT.HK A26-07-52's stated scope and are noted here only as release context, not as part of this threat record.

MITRE ATT&CK techniques used in TL-2026-1782

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Discovery

T1082 System Information Discovery

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution; T1204 User Execution

Impact

T1489 Service Stop; T1499 Endpoint Denial of Service; T1565 Data Manipulation

Persistence

T1505 Server Software Component

Credential Access

T1552 Unsecured Credentials

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

  • PHP Group — PHP (ext-phar extension)
    Vulnerable versions: 8.2.x < 8.2.33; 8.3.x < 8.3.33; 8.4.x < 8.4.24; 8.5.x < 8.5.9
    Fixed in: 8.2.33; 8.3.33; 8.4.24; 8.5.9
  • PHP Group — PHP (ext-gd extension / bundled libgd)
    Vulnerable versions: 8.2.x < 8.2.33; 8.3.x < 8.3.33; 8.4.x < 8.4.24; 8.5.x < 8.5.9
    Fixed in: 8.2.33; 8.3.33; 8.4.24; 8.5.9
  • PHP Group — PHP (ext-pgsql extension)
    Vulnerable versions: 8.2.x < 8.2.33; 8.3.x < 8.3.33; 8.4.x < 8.4.24; 8.5.x < 8.5.9
    Fixed in: 8.2.33; 8.3.33; 8.4.24; 8.5.9
  • PHP Group — PHP (ext-bcmath extension)
    Vulnerable versions: 8.4.x < 8.4.24; 8.5.x < 8.5.9
    Fixed in: 8.4.24; 8.5.9

Remediation for Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

Patches

  • PHP 8.5.9 (2026-07-30) - fixes all four CVEs
  • PHP 8.4.24 (2026-07-30) - fixes all four CVEs
  • PHP 8.3.33 (2026-07-30) - fixes CVE-2026-7260, CVE-2026-9672, CVE-2026-17543
  • PHP 8.2.33 (2026-07-30) - fixes CVE-2026-7260, CVE-2026-9672, CVE-2026-17543

Immediate actions

  • Upgrade PHP to 8.5.9, 8.4.24, 8.3.33, or 8.2.33 (or later) on all affected hosts
  • Where upgrade is not immediately possible, disable or restrict use of the phar:// stream wrapper and Phar class for untrusted archive input
  • Audit any code path that builds pg_select()/pg_insert()/pg_update()/pg_delete() calls from user-controlled string values and add explicit input validation as a compensating control
  • Restrict or sandbox image-processing pipelines (GD/libgd GIF decode) that handle untrusted user-uploaded images until patched

Workarounds

  • Set standard_conforming_strings appropriately and avoid constructing pg_* queries from unsanitized user input as a stopgap for CVE-2026-17543
  • Reject or pre-validate uploaded .phar/tar archives and GIF images at the application layer before they reach vulnerable extensions

Longer-term hardening

  • Adopt parameterized/prepared statements exclusively for all PostgreSQL access from PHP rather than relying on pg_* convenience-function escaping
  • Track PHP's supported branches and maintain a patch cadence aligned with PHP's security-release schedule
  • Add fuzzing/regression coverage for Phar symlink handling, GD image decoding, and BCMath scale/truncation edge cases in any custom PHP builds or forks
  • Monitor php-fpm/php-cgi worker crash-and-restart rates as an operational signal of possible exploitation attempts against memory-corruption or DoS bugs

CVEs associated with Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544

Weaknesses (CWE) in Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

CWE-674, CWE-400, CWE-121, CWE-89, CWE-787

Timeline of Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

  • PHP project commits fixes for all four vulnerabilities (Phar circular-symlink crash, libgd GIF LZW bug, pgsql SQL injection, BCMath OOB write) to php-src master and the 8.2/8.3/8.4/8.5 branches within a roughly three-hour window (commits including news-web.php.net/php.cvs/140252, 140291, 140301).
  • The same PHP 8.5.9 and 8.4.24 point releases that fix the four GovCERT.HK-flagged CVEs also bundle fixes for multiple unrelated vulnerabilities per the official PHP ChangeLog -- including OpenSSL AES-WRAP-PAD memory corruption (CVE-2026-14355), an MBString mb_ereg_search_init() NULL pointer dereference (CVE-2026-7259), a DOM duplicate-xmlns-declaration issue (CVE-2026-7263), and a Standard-extension signed integer overflow (CVE-2026-7568) -- confirming this was a broader coordinated security release, not a single-issue patch.
  • NVD publishes CVE record entries for CVE-2026-7260 (CVSS v3.1 5.5 MODERATE, AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H; CVSS v4.0 5.4 MEDIUM), CVE-2026-17543 (CVSS v4.0 8.1 HIGH, network vector), and CVE-2026-17544 (CVSS v4.0 8.1 HIGH, published 2026-07-30T12:17:27Z); all three carry an 'Awaiting Analysis' status pending full NVD review. CVE-2026-9672 (libgd) has no NVD CVSS/CWE record at analysis time.
  • PHP 8.3.33 and PHP 8.2.33 are released for the legacy-supported branches, bundling fixes for CVE-2026-7260, CVE-2026-9672, and CVE-2026-17543.
  • PHP 8.5.9 and PHP 8.4.24 are released, bundling fixes for all four CVEs (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544).
  • GitHub Security Advisories GHSA-vc5h-9ppw-p5f3 (CVE-2026-7260, Phar), GHSA-7qpv-r5mr-78m4 (CVE-2026-17543, pgsql), and GHSA-x692-q9x7-8c3f (CVE-2026-17544, BCMath) are published with technical detail, PoC, and CWE/CVSS data.
  • NVD last-modified timestamps advance to 2026-07-31 for CVE-2026-17543 and to 2026-07-31T04:16:48Z for CVE-2026-17544, reflecting continued NVD analyst review the day after initial publication.
  • CISA Known Exploited Vulnerabilities catalog (1,656 entries as of 2026-07-29) is checked and does not list any of CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, or CVE-2026-17544, indicating no confirmed active in-the-wild exploitation at time of analysis.
  • GovCERT.HK publishes Security Alert A26-07-52, 'Multiple Vulnerabilities in PHP,' summarizing the four-CVE release and rating impact as denial of service or tampering without an independent CVSS assessment.

Sources cited for Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52)

Detection coverage for TL-2026-1782

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1782 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats