No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes. | |
| Title | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS | |
| Weaknesses | CWE-67 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2026-09-25T20:43:34.157Z
Reserved: 2026-07-27T10:15:15.310Z
Link: CVE-2026-17545
Updated: 2026-09-25T20:43:29.843Z
Status : Received
Published: 2026-09-25T21:17:23.253
Modified: 2026-09-25T21:17:23.253
Link: CVE-2026-17545
No data.
OpenCVE Enrichment
No data.
-
CWE-67
Improper Handling of Windows Device Names