Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename therefore reaches CreateFileW() and opens a device instead of the regular file the application expected, which can block or hang the request and exhaust worker processes. | |
| Title | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS | |
| Weaknesses | CWE-67 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2026-09-25T20:43:34.157Z
Reserved: 2026-07-27T10:15:15.310Z
Link: CVE-2026-17545
Updated: 2026-09-25T20:43:29.843Z
Status : Received
Published: 2026-09-25T21:17:23.253
Modified: 2026-09-25T21:17:23.253
Link: CVE-2026-17545
No data.
OpenCVE Enrichment
No data.