Skip to main content
UNKNOWN

CVE-2026-7260

Stack overflow in phar with circular symlinks

CVSS v3

—

Unknown

EPSS Score

0.1 %

exploit probability, as of 2026-10-01

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Description

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Technical details

Published
2026-07-30
Last Modified
2026-07-30

Frequently asked questions

What is CVE-2026-7260?

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Is CVE-2026-7260 actively exploited?

Active exploitation of CVE-2026-7260 has not been confirmed. Its EPSS score was 0.1% on 2026-10-01, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-7260?

A CVSS score has not been assigned to CVE-2026-7260 yet.

Is CVE-2026-7260 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key