Back

CVE-2016-7398

CRITICAL

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

Published: Sep 6, 2019 Modified: Jun 17, 2026
CWE-704

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (10)

Vendor Product Version
php ext-http *
php ext-http * ≥ 3.0.0
php ext-http 2.6.0
php ext-http 2.6.0
php ext-http 2.6.0
php ext-http 2.6.0
php ext-http 3.1.0
php ext-http 3.1.0
php ext-http 3.1.0
php ext-http 3.1.0

GitHub Security Advisory GHSA-jx2x-3hjr-6vp8

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.80%

Top 6% most likely to be exploited

Threat Score 41.2 / 100

Data Sources

NVD EPSS GitHub