AI description
It appears there might be a slight typo in the CVE number provided. Based on popular articles, a vulnerability identified as CVE-2025-12183 has been widely discussed. This vulnerability affects `org.lz4:lz4-java` versions 1.8.0 and earlier. CVE-2025-12183 involves out-of-bounds memory operations, which can be triggered by remote attackers providing untrusted compressed input. This flaw can lead to a denial of service and allow attackers to read adjacent memory. The issue specifically impacts programs utilizing the `LZ4_decompress_fast` API, also known as the "fast" decompressor, which lacks boundary checks when processing untrusted inputs.
- Description
- The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.
- Source
- security@php.net
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 3.4
- Impact score
- 1.4
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Severity
- LOW
- security@php.net
- CWE-122
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16
PHP 8.4.26 released - 64 fixes in 25 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/ZrPmRpxg1x
@php_net
26 Sept 2026
2637 Impressions
9 Retweets
30 Likes
3 Bookmarks
0 Replies
1 Quote
CVE-2025-1218 The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL … https://t.co/XuCCppyPuK
@CVEnew
26 Sept 2026
1043 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
PHP 8.2.34 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/Or4opPr46m
@php_net
25 Sept 2026
4236 Impressions
4 Retweets
22 Likes
1 Bookmark
0 Replies
0 Quotes
PHP 8.3.35 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/V3HAM01AXX
@php_net
25 Sept 2026
3811 Impressions
6 Retweets
28 Likes
3 Bookmarks
0 Replies
0 Quotes
PHP 8.5.11 released - 57 fixes in 22 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/sJtYkJM8Hd
@php_net
24 Sept 2026
4391 Impressions
13 Retweets
47 Likes
7 Bookmarks
0 Replies
0 Quotes