{"id":"CVE-2026-93682","published":"2026-09-25T20:17:47.597","lastModified":"2026-09-29T21:27:41.130","description":"When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.","cvssScore":5.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","cwes":["CWE-125"],"vendors":[],"products":[],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f","tags":[]},{"url":"https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f","tags":[]}],"exploitRefs":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f","tags":[]},{"url":"https://github.com/php/php-src/security/advisories/GHSA-7875-c8px-7q5f","tags":[]}],"hasPoc":true,"ai":null}