Vulnerability Details CVE-2026-17544
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-17544