CVE-2025-14177 - CVE House
Back to Database
Status published Medium CVE-2025-14177

Information Leak of Memory in getimagesize

Vulnerability Description

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14177

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Nikita Sveshnikov (Positive Technologies)

Affected Vendor

Affected Software

PHP
Vulnerable Versions:
8.1.*, 8.2.*, 8.3.*, 8.4.*, 8.5.*

Timeline

Official Publish: December 27th, 2025
Last Modified: December 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)