{"id":"CVE-2026-17544","aliases":["BIT-php-2026-17544","BIT-php-min-2026-17544"],"url":"https://o3.security/vulnerability/CVE-2026-17544","summary":"Out-of-bounds write in bccomp() via crafted operand and scale","details":"Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.","published":"2026-08-17T05:47:59.777Z","modified":"2026-08-17T08:11:02.828290586Z","cvss":null,"epss":{"score":0.00522,"percentile":0.41907,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Bitnami","name":"libphp","fixedVersion":"8.4.24"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/php/php-src/security/advisories/GHSA-x692-q9x7-8c3f"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17544"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T08:11:02.828290586Z"}}