{
  "cves": [
    "CVE-2026-6722",
    "CVE-2026-6735",
    "CVE-2026-7258",
    "CVE-2026-7261",
    "CVE-2026-7262",
    "CVE-2026-7568"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "libzip\n[1.6.1-1]\n- update to 1.6.1\n- enable lzma support\n\nphp\n[7.4.33-4]\n- Fix XSS within status endpoint\n  CVE-2026-6735\n- Fix Stale SOAP_GLOBAL(ref_map) pointer with Apache Map\n  CVE-2026-6722\n- Fix Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION\n  CVE-2026-7261\n- Fix Broken Apache map value NULL check\n  CVE-2026-7262\n- Fix Signed integer overflow of char array offset\n  CVE-2026-7568\n- Fix Consistently pass unsigned char to ctype.h functions\n  CVE-2026-7258\n\nphp-pear\n[1:1.10.13-1]\n- update PEAR to 1.10.13\n- update Archive_Tar to 1.4.14\n\nphp-pecl-apcu\n[5.1.18-1]\n- update to 5.1.18\n\nphp-pecl-rrd\n[2.0.1-1]\n- build for RHEL 8\n\nphp-pecl-xdebug\n[2.9.5-1]\n- update to 2.9.5\n\nphp-pecl-zip\n[1.18.2-1]\n- update to 1.18.2",
  "id": "ELSA-2026-34354",
  "ovalId": "oval:com.oracle.elsa:def:202634354",
  "source": "oracle_linux",
  "title": "ELSA-2026-34354:  php:7.4 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-34354.html"
}