logo

Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

ID: 793f4d16-c47f-5232-aef2-2f159dfb1b34

STIX ID: report--793f4d16-c47f-5232-aef2-2f159dfb1b34

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Dhivya

...
...

**Executive summary:** Two critical memory-safety flaws in PHP's ext/standard image-processing functions were disclosed: CVE-2025-14177 allows leakage of uninitialized heap memory via getimagesize when processing large multi-chunk JPEG APP segments, and a heap buffer overflow in iptcembed can be triggered by streams (e.g., FIFOs) or oversized input causing out-of-bounds writes; both have practical PoCs and patches are available for affected PHP 8.1–8.5 series.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.