{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T02:40:13.135","vulnerabilities":[{"cve":{"id":"CVE-2025-14178","sourceIdentifier":"security@php.net","published":"2025-12-27T20:15:40.570","lastModified":"2026-06-17T08:35:27.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server."}],"affected":[{"source":"security@php.net","affectedData":[{"vendor":"PHP Group","product":"PHP","defaultStatus":"affected","packageName":"php","versions":[{"version":"8.1.*","lessThan":"8.1.34","versionType":"semver","status":"affected"},{"version":"8.2.*","lessThan":"8.2.30","versionType":"semver","status":"affected"},{"version":"8.3.*","lessThan":"8.3.29","versionType":"semver","status":"affected"},{"version":"8.4.*","lessThan":"8.4.16","versionType":"semver","status":"affected"},{"version":"8.5.*","lessThan":"8.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@php.net","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-29T16:00:50.197017Z","id":"CVE-2025-14178","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@php.net","type":"Secondary","description":[{"lang":"en","value":"CWE-190"},{"lang":"en","value":"CWE-787"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.34","matchCriteriaId":"56FCF002-3946-40DF-A774-75C6DDE6CA26"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.30","matchCriteriaId":"AB314013-4F2F-40F0-968B-35FEC22CC8A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"8.3.29","matchCriteriaId":"DAD5402D-688D-44AA-B083-5157FDC53D7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"8.4.16","matchCriteriaId":"8813328B-AC06-4060-916F-CD27144F41E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.1","matchCriteriaId":"E56CD990-B79E-4253-B810-13787B23B028"}]}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-h96m-rvf9-jgm2","source":"security@php.net","tags":["Vendor Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00019.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}