CVE-2025-1735

Name
CVE-2025-1735
Description
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. ThisĀ could cause crashes if Postgres server rejects the string as invalid.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@php.net https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/07/11/4

Match rules

CPE URI Source package Min version Max version
php >= 8.1.* < 8.1.33
php >= 8.2.* < 8.2.29
php >= 8.3.* < 8.3.23
php >= 8.4.* < 8.4.10

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
php84 edge-community 8.4.9-r0 Andy Postnikov <apostnikov@gmail.com> fixed
php84 3.22-community 8.4.10-r0 None fixed
php84 3.22-community 8.4.9-r0 None fixed
php83 edge-community 8.3.23-r0 Andy Postnikov <apostnikov@gmail.com> fixed
php83 3.22-community 8.3.23-r0 None fixed
php82 edge-community 8.2.29-r0 Andy Postnikov <apostnikov@gmail.com> fixed
php82 3.22-community 8.2.29-r0 Andy Postnikov <apostnikov@gmail.com> fixed