PHP ext-phar Symlink Recursion (<=v8.2.33/8.3.33/8.4.24/8.5.9)
CVE-2026-7260 Published on July 30, 2026

Stack overflow in phar with circular symlinks
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-7260 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
ACTIVE

Weakness Type

What is a Stack Overflow Vulnerability?

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CVE-2026-7260 has been classified to as a Stack Overflow vulnerability or weakness.


Products Associated with CVE-2026-7260

stack.watch emails you whenever new vulnerabilities are published in PHP or Canonical Ubuntu Linux. Just hit a watch button to start following.

PHP
 
 

Affected Versions

PHP Group PHP: