What is CVE-2026-7260?
This vulnerability arises from circular symbolic links in phar archives, which can trigger unbounded recursion, exhaust the C stack, and crash the PHP process. Affected systems running the specified PHP versions may lose service availability, making it essential to upgrade to the recommended patched releases.
Azərbaycanca: Bu zəiflik, phar arxivlərindəki dairəvi simvolik keçidlərin (circular symbolic links) PHP prosesinin C stack-ni tükəndərərək çökməsinə səbəb olması ilə bağlıdır. Təsirə məruz qalan PHP versiyalarını istifadə edən sistemlər xidmət dayanıqlılığını itirə bilər, buna görə də göstərilən son təhlükəsizlik yeniləmələrinə yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
How does CVE-2026-7260 affect the PHP process?
CVE-2026-7260 arises from circular symbolic links in phar archives, which trigger unbounded recursion, exhaust the C stack, and crash the PHP process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.