In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.
The source code contains comments that do not accurately describe or explain aspects of the portion of the code with which the comment is associated.
Link | Tags |
---|---|
https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc | vendor advisory exploit |
https://security.netapp.com/advisory/ntap-20250523-0007/ |