logo

Weaponized JPEG Images Could Enable Exploitation of PHP Memory Flaws

ID: da219bd7-c073-5d89-a0d9-21b120b16eb1

STIX ID: report--da219bd7-c073-5d89-a0d9-21b120b16eb1

Feed Name: Cyber Press

Threat Score
55/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Divya

...
...

**Executive summary:** Researchers discovered two memory-safety flaws in PHP's JPEG handling—CVE-2025-14177 in getimagesize() that can leak heap memory via multi-chunk APP segments, and a heap buffer overflow in iptcembed() that can be triggered by FIFO/pipe or race conditions—affecting multiple PHP 8.x releases; both were responsibly disclosed and patched, and users processing untrusted JPEGs should upgrade to the fixed versions and avoid passing untrusted files via php://filter or FIFO-backed paths until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.