AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-21707

MEDIUM · CVSS 5.3 EPSS 25.95%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-21707
Severity
MEDIUM
CVSS
5.3
EPSS
25.95%

Original NVD Description

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.