PHP NULL Pointer Dereference Vulnerability - CVE-2026-7259
In PHP versions 8.2. before 8.2.31 8.3. before 8.3.31 8.4. before 8.4.21 and 8.5. before 8.5.6 a mismatch between encoding lists in Oniguruma and mbfl leads toa NULL pointer dereference resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed tomb_regex_encoding().