peter bassill · operator
$ cve CVE-2016-7398 JSON

CVE-2016-7398

9.8
CRITICAL · CVSS 3.1 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.8% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-704
On CISA KEVno
Public exploitnone known
Published2019-09-06
Last modified2026-06-17

Affected (1)

VendorProduct
phpext-http

References

→ the Explorer  ·  watch your stack  ·  NVD