AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-31625

HIGH · CVSS 8.1 EPSS 3.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-31625
Severity
HIGH
CVSS
8.1
EPSS
3.44%

Original NVD Description

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.