CVE-2026-17544

Communications: Out-of-bounds Write (CVE-2026-17544)

criticalPoCEPSS 0.4%

Affected

  • bitnami/php-min 8.4.0..*
  • bitnami/php-min 8.5.0..*

Description

A flaw was found in PHP. A remote attacker could exploit this vulnerability by providing specially crafted inputs to the `bccomp()` function. This could lead to an out-of-bounds write, resulting in stack and heap corruption. Such memory corruption can enable arbitrary code execution, allowing the attacker to take control of the affected system.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

OracleCommunications
Cloud Native Core Security Edge Protection Proxy 25.2.201Cloud Native Core Security Edge Protection Proxy 26.1.200MetaSolv Solution Module 70.0.0Operations Monitor 6.1Service Catalog and Design 8.0-8.3Unified Assurance 6.1.1-7.0.0Unified Assurance 7.0.0

Metrics

9.8
Source: nvd-v3
34.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
PoC (publicly reported)
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-17 05:53 UTC
CWE-787

Weakness classes (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-05 19:40 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CPE Configuration: OR *cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from (including) 8.4.0 up to (excluding) 8.4.24 *cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (excluding) 8.5.9
    • Reference Type: PHP Group: https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f Types: Vendor Advisory
  2. New CVE Received2026-07-30 12:17 UTC· security@php.net
    • Affected: PHP
    • Description: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
    • CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
    • CWE: CWE-787

Linked advisories