Looking for the vulnerability index of Invicti's legacy products?
PHP Out-of-bounds Read Vulnerability - CVE-2026-6104 - Vulnerability Database

PHP Out-of-bounds Read Vulnerability - CVE-2026-6104

Critical
Reference: CVE-2026-6104
Title: PHP Out-of-bounds Read Vulnerability
Overview:

In PHP versions 8.4. before 8.4.21 and 8.5. before 8.5.6 when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions the code incorrectly assumes that whenstrncasecmp()returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory potentially causing a crash or information disclosure or crash.Affected functions include mb_convert_encoding() mb_detect_encoding() mb_convert_variables() and mb_detect_order() as well as the mbstring.detect_order and mbstring.http_output INI settings.