#VU120274 Input validation error in PHP
Published: December 23, 2025
PHP
PHP Group
Description
The vulnerability allows a remote attacker to tamper with application workflow.
The vulnerability exists due to insufficient validation of user-supplied input in dns_get_record() and other DNS functions. A remote attacker can pass specially crafted input with a NULL byte character to the application and tamper with application;s workflow, potentially performing SSRF attack.