CVE-2025-14177
Last modified
CVE-2025-14177 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 8.1.0, < 8.1.34 |
| Php | Php | >= 8.2.0, < 8.2.30 |
| Php | Php | >= 8.3.0, < 8.3.29 |
| Php | Php | >= 8.4.0, < 8.4.16 |
| Php | Php | 8.5.0 |
References
- https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-14177?
How severe is CVE-2025-14177?
How do I fix CVE-2025-14177?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1417In Proget MDM, a low-privileged user can access information …4.6
- CVE-2025-14170The Vimeo SimpleGallery plugin for WordPress is vulnerable t…4.3
- CVE-2025-14172The WP Page Permalink Extension plugin for WordPress is vuln…6.5
- CVE-2025-14173The Perfit WooCommerce plugin for WordPress is vulnerable to…5.3
- CVE-2025-14174Out of bounds memory access in ANGLE in Google Chrome on Mac…8.8
- CVE-2025-14175A vulnerability in the SSH server of TP-Link TL-WR820N v2.80…6.5
- CVE-2025-14178In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.…8.2
- CVE-2025-14179In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.…9.8
- CVE-2025-1418A low-privileged user can access information about profiles …5.1
- CVE-2025-14180In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.…7.5
- CVE-2025-14182A vulnerability has been found in Sobey Media Convergence Sy…9.8
- CVE-2025-14183A vulnerability was found in SGAI Space1 NAS N1211DS up to 1…4.3
Are you affected by CVE-2025-14177?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
