# Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)

> PHP shipped coordinated security releases (8.2.33, 8.3.33, 8.4.24, 8.5.9, all dated 2026-07-30) fixing four vulnerabilities: a Phar circular-symlink stack-exhaustion crash, a bundled-libgd GIF LZW decompression memory-corruption bug, a PostgreSQL extension SQL-injection flaw via backslash escape-string breakout, and a BCMath bccomp() out-of-bounds write. GovCERT.HK Alert A26-07-52 rates the combined impact as denial of service and tampering; NVD scores two of the four CVEs 8.1/10 (CVSS v4, HIGH), and none currently appear in the CISA KEV catalog.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1782
- **ID:** TL-2026-1782
- **Severity:** HIGH (CVSS 8.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544

## Description

On 2026-07-28 the PHP project committed fixes for four independently-discovered vulnerabilities to php-src master and all four supported release branches within a roughly three-hour window; the fixes shipped publicly on 2026-07-30 as PHP 8.5.9, 8.4.24, 8.3.33, and 8.2.33. GovCERT.HK published Security Alert A26-07-52 on 2026-07-31 summarizing the release without individual CVE technical detail, stating only that exploitation "could lead to denial of service or tampering."

1) CVE-2026-7260 (Phar, CWE-121/CWE-400/CWE-674, CVSS 5.4 v4, GHSA-vc5h-9ppw-p5f3): phar_get_link_source() in ext/phar/util.c recursively resolves symbolic links inside phar (PHP Archive) files with no depth limit or cycle detection. A crafted tar-based .phar archive containing mutually-referencing symlinks (file_a -> file_b -> file_a) drives unbounded recursion when content is retrieved (e.g. via Phar::getContent()), exhausting the C call stack and crashing the PHP process. The same release also fixed inconsistent handling of the magic ".phar" directory (paths merely starting with ".phar" vs the true magic path) across file/directory creation, copy, ArrayAccess, stream lookup, iteration, and extraction. Credited to Calvin Young (eWalker Consulting) and Enoch Chow (Isomorph Cyber).

2) CVE-2026-9672 (bundled libgd/GD extension, GIF decoder): a patch authored by Pierre Joye and committed by Ilija Tovilo on 2026-07-28 fixed ext/gd/libgd/gd_gif_in.c's LWZReadByte_() LZW-decompression routine. The code incorrectly executed `sd->table[0][i] = sd->table[1][0] = 0;` instead of `sd->table[0][i] = sd->table[1][i] = 0;` when initializing the GIF LZW code table, and was missing a bounds-check return path (an added `return -2;`). A maliciously crafted GIF image processed by the GD extension (e.g. an attacker-supplied image upload later thumbnailed/re-encoded by a web application) can corrupt the LZW table state, leading to memory corruption during decode. NVD had not yet published a CVSS score/CWE for this CVE at analysis time ("Awaiting Analysis"); given the memory-safety class of the bug (analogous to historical GD/GdkPixbuf GIF LZW flaws such as CVE-2021-44648), it is assessed here as at least a denial-of-service risk with unconfirmed code-execution potential pending a full NVD writeup.

3) CVE-2026-17543 (pgsql extension, CWE-89, CVSS 8.1 v4 HIGH, GHSA-7qpv-r5mr-78m4): php_pgsql_convert() in ext/pgsql/pgsql.c (~lines 4751-4757), used by pg_insert(), pg_update(), pg_select(), and pg_delete(), wraps escaped values in PostgreSQL escape-string constants (E'...') using PQescapeStringConn(). PQescapeStringConn() does not escape backslashes when the server has standard_conforming_strings = on -- the PostgreSQL default since version 9.1 -- allowing an attacker-controlled value ending in a backslash to prematurely terminate the E'...' literal and inject arbitrary SQL. Published PoC: `pg_select($db, 'user', ['name' => "zzz\\' OR 1=1 --"])` renders as `SELECT * FROM "user" WHERE "name"='zzz\'' OR 1=1 --';`, returning all rows. The fix switches php_pgsql_convert() to use non-escaping string constants so backslash breakout is no longer possible. Reported by ExPatch-LLC; fix by iluuu1994, reviewed by mbeccati, analysis by alexandre-daubois.

4) CVE-2026-17544 (bcmath extension, CWE-121/CWE-787, CVSS 8.1 v4 HIGH, GHSA-x692-q9x7-8c3f): bc_str2num() in ext/bcmath/libbcmath/src/str2num.c mishandles trailing-zero truncation when a caller-specified scale shortens a numeric string. The code adjusts str_scale (`str_scale -= fractional_end - fractional_new_end;`) but fails to also adjust fractional_end, so bc_copy_and_toggle_bcd() subsequently copies BCD data past the shortened allocation -- an out-of-bounds write reachable via bccomp() with attacker-controlled operand and scale, corrupting stack or heap memory depending on whether BCMath's arena allocator or a heap fallback backs the buffer. Reported by recepasan; analysis by iluuu1994. Only PHP 8.4.x (before 8.4.24) and 8.5.x (before 8.5.9) are affected per the GHSA advisory.

All four fixes are cumulative across the affected branches; administrators running any PHP branch prior to the patched point releases should upgrade. None of the four CVEs are present in the CISA KEV catalog (1,656 entries as of 2026-07-29) and no public reports of in-the-wild exploitation were identified, consistent with GovCERT.HK's decision not to flag this as a High Threat alert.

Direct NVD verification confirms CVE-2026-7260's actual severity is materially lower than the other three: CVSS v3.1 5.5 (MODERATE), vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, and CVSS v4.0 5.4 (MEDIUM), vector AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H -- both scorings mark the attack vector Local (not Network) and require user interaction, consistent with the Phar bug only being reachable when an application or administrator actively opens/extracts an attacker-supplied .phar archive rather than being remotely triggerable like the pgsql and BCMath issues. CVE-2026-17543 and CVE-2026-17544 both independently confirm CVSS v4.0 8.1 (HIGH), Network attack vector, no privileges/no user interaction required. All four CVE records carried NVD 'Awaiting Analysis' status as of 2026-07-31, and CVE-2026-9672 (libgd) still had no published NVD CVSS/CWE record at analysis time.

The same PHP 8.5.9 / 8.4.24 point releases that carry these four fixes also bundle patches for several unrelated vulnerabilities per the official PHP ChangeLog -- OpenSSL AES-WRAP-PAD memory corruption (CVE-2026-14355), an MBString mb_ereg_search_init() NULL pointer dereference (CVE-2026-7259), a DOM duplicate-xmlns-declaration issue (CVE-2026-7263), and a Standard-extension signed integer overflow (CVE-2026-7568) -- confirming this was part of PHP's routine broader coordinated security-release cadence rather than an emergency single-issue patch; those four CVEs are outside GovCERT.HK A26-07-52's stated scope and are noted here only as release context, not as part of this threat record.

## MITRE ATT&CK

- T1592 Gather Victim Host Information
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1213 Data from Information Repositories
- T1499 Endpoint Denial of Service
- T1565 Data Manipulation
- T1588 Obtain Capabilities
- T1595 Active Scanning
- T1204 User Execution
- T1505 Server Software Component
- T1005 Data from Local System
- T1489 Service Stop

## Sources

- [GovCERT.HK Security Alert (A26-07-52): Multiple Vulnerabilities in PHP](https://www.govcert.gov.hk/en/alerts_detail.php?id=1992)
- [PHP ChangeLog (8.x series)](https://www.php.net/ChangeLog-8.php)
- [GHSA-vc5h-9ppw-p5f3: Crash via recursive symlinks (Phar)](https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3)
- [GHSA-7qpv-r5mr-78m4: SQL injection via E'...' backslash breakout (pgsql)](https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4)
- [GHSA-x692-q9x7-8c3f: Out-of-bounds write in bccomp() (BCMath)](https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f)
- [php.cvs: php-src master: libgd patch for CVE-2026-9672](https://news-web.php.net/php.cvs/140252)
- [php.cvs: php-src php-8.3.33: libgd patch for CVE-2026-9672](https://news-web.php.net/php.cvs/140291)
- [php.cvs: php-src PHP-8.4.24: libgd patch for CVE-2026-9672](https://news-web.php.net/php.cvs/140301)
- [PHP 8.5.9 and 8.2.33 Security Updates Drop Alongside 8.6 Alpha 3](https://www.linuxcompatible.org/story/php-859-and-8233-security-updates-drop-alongside-86-alpha-3)
- [CISA Known Exploited Vulnerabilities Catalog (checked - no match)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1782
