Description
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Published: 2026-07-03
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer allocation flaw in PHP’s OpenSSL extension when the AES‑WRAP‑PAD algorithm is used. The routine calculates the output buffer size based only on the plaintext length and fails to account for the padding expansion defined by RFC 5649. This heap‑based buffer overflow allows OpenSSL to write past the end of the allocated buffer, corrupting heap metadata and causing the PHP process to abort. The attack results in an application crash rather than code execution or data disclosure.

Affected Systems

The flaw affects PHP 8.2.* before 8.2.32, PHP 8.3.* before 8.3.32, PHP 8.4.* before 8.4.23, and PHP 8.5.* before 8.5.8. Systems running these versions with the default OpenSSL extension are vulnerable if they call openssl_encrypt using the AES‑WRAP‑PAD algorithm.

Risk and Exploitability

The CVSS score of 5.6 places the vulnerability in the moderate range, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. The buffer overflow can be triggered by supplying malicious data that causes openssl_encrypt to use AES‑WRAP‑PAD, leading to denial‑of‑service via application abort. An attacker must control input to a PHP application that uses the vulnerable routine, which limits the attack surface.

Generated by OpenCVE AI on July 21, 2026 at 09:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PHP to 8.2.32, 8.3.32, 8.4.23, 8.5.8, or a newer release that contains the fix.
  • If an upgrade cannot be performed, avoid using the AES‑WRAP‑PAD algorithm in openssl_encrypt calls within the application.
  • Validate and sanitise input data before passing it to openssl_encrypt, ensuring it meets expected length and format constraints to reduce the chance of malformed payloads triggering the overflow.

Generated by OpenCVE AI on July 21, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4669-1 php8.2 security update
Debian DSA Debian DSA DSA-6377-1 php8.4 security update
History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Php
Php php
Vendors & Products Php
Php php

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
Title ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: php

Published:

Updated: 2026-07-06T13:57:58.387Z

Reserved: 2026-07-01T17:52:41.706Z

Link: CVE-2026-14355

cve-icon Vulnrichment

Updated: 2026-07-04T15:25:16.999Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow