PHP NULL Pointer Dereference Vulnerability - CVE-2026-7262
In PHP versions 8.2. before 8.2.31 8.3. before 8.3.31 8.4. before 8.4.21 and 8.5. before 8.5.6 when a SOAP server has a typemap configured the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads todereferences a NULL pointer causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process resulting in denial of service.