Skip to main content

Malformed GIF files processed with GD extension lead to potential arbitrary code execution

Publication Date 2026-08-01
Severity High
Type Remote Code Execution
Affected PHP Versions
  • 7.2.0-7.2.34
  • 7.3.0-7.3.33
  • 7.4.0-7.4.33
  • 8.1.0-8.1.34
  • 8.2.0-8.2.32
  • 8.3.0-8.3.32
  • 8.4.0-8.4.23
  • 8.5.0-8.5.8
Fixed Product Versions
  • ZendPHP 7.2
  • ZendPHP 7.3
  • ZendPHP 7.4
  • ZendPHP 8.1
  • ZendPHP 8.2
  • ZendPHP 8.3
  • ZendPHP 8.4
  • ZendPHP 8.5
  • ZendServer 2021.4.7

CVE Details

A vulnerability in libgd2 allows malformed GIF files to execute arbitrary code (RCE), potentially leading to a Denial of Service (DoS).

Recommendations

If you process GIF images using the GD extension in PHP, we recommend upgrading immediately to a version containing a patch.