HIGH

CVE-2022-31626

CVSS v3

8.8

HIGH

EPSS Score

14.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

Technical details

Published
6/16/2022

Frequently asked questions

What is CVE-2022-31626?

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

Is CVE-2022-31626 actively exploited?

Active exploitation of CVE-2022-31626 has not been confirmed. The EPSS score is 14.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-31626?

CVE-2022-31626 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-31626 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.