---
id: CVE-2026-91765
title: >-
  cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level
  with no depth limit
summary: >-
  cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level
  with no depth limit. An unauthenticated attacker can post a SOAP request
  containing tens of thousands of nested elements to any SoapServer endpoint,
  exhaust th…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
  - CWE-770
vendor: PHP Group
product: ext-soap
affected:
  - ext-soap >= 8.2.* < 8.2.34
  - ext-soap >= 8.3.* < 8.3.35
  - ext-soap >= 8.4.* < 8.4.26
  - ext-soap >= 8.5.* < 8.5.11
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T21:17:24.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91765'
references:
  - url: 'https://github.com/php/php-src/security/advisories/GHSA-rgrp-mwpx-f6rm'
    label: security@php.net
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91765.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91765'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2541646'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91765'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91765'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70720'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-09-25T21:19:40.145Z'
patched:
  - hardened_images
---

## Overview

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:70720** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70720)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91765.json)
