Skip to main content
MEDIUM

CVE-2025-6491

CVSS v3

5.9

MEDIUM

EPSS Score

1.0 %

exploit probability, as of 2026-10-07

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

Technical details

Published
2025-07-13
Last Modified
2025-11-04

Frequently asked questions

What is CVE-2025-6491?

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

Is CVE-2025-6491 actively exploited?

Active exploitation of CVE-2025-6491 has not been confirmed. Its EPSS score was 1.0% on 2026-10-07, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-6491?

CVE-2025-6491 has a CVSS v3 base score of 5.9 (MEDIUM severity).

Is CVE-2025-6491 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key