EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to correlated intelligence
Vulnerability

CVE-2026-91767

Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.

Sharing
PUBLIC-OSINT
Confidence
100
Source
The CVE Program
Updated
26/09/2026 05:15

Description

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

STIX identifiervulnerability--499d12fb-77ce-5b8c-bc75-aa4558b4e279
First observation-
Last observation-
Known relationships8

Aliases and classifications

CWE-122Heap-based Buffer Overflow

Minimised technical details

No raw data
cisa kev
False
cvss score
6.5
cvss vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss severity
MEDIUM
EudorIA correlation

Intel catalogue

The vulnerability is also available in the EudorIA editorial catalogue.

Open EudorIA analysis

Presence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.