Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6088-1 | php8.4 security update |
Debian DSA |
DSA-6154-1 | php8.2 security update |
Ubuntu USN |
USN-7953-1 | PHP vulnerabilities |
Fri, 09 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php
Php php |
|
| Vendors & Products |
Php
Php php |
Mon, 29 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Sat, 27 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server. | |
| Title | NULL Pointer Dereference in PDO quoting | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-12-29T16:00:11.239Z
Reserved: 2025-12-06T06:43:11.174Z
Link: CVE-2025-14180
Updated: 2025-12-29T16:00:06.251Z
Status : Analyzed
Published: 2025-12-27T20:15:40.717
Modified: 2026-01-09T20:23:40.930
Link: CVE-2025-14180
OpenCVE Enrichment
Updated: 2025-12-29T22:33:26Z
Debian DSA
Ubuntu USN