
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9672 is a reserved CVE associated with a vulnerability in PHP's GD extension, addressed through an upgrade of the underlying libgd library. The CVE was first detected in threat intelligence feeds on July 28, 2026, with activity observed through July 31, 2026. Full vulnerability details have not yet been publicly disclosed, as the CVE status remains "Reserved." The estimated CVSS severity category is Medium, though an official score has not been published (Feedly, PHP Commit).
The vulnerability resides in PHP's GD image processing extension and was remediated by upgrading the bundled libgd library. The fix is visible in the PHP source repository commit 416985389d0a5c7ad97161c911a53f0e6df7bbbe, which references the libgd upgrade as the resolution (PHP Commit). The specific root cause (CWE classification), attack vector, and exploitation mechanics have not been publicly disclosed at this time, as the CVE remains in a reserved state. The vulnerability appears to have been addressed in PHP 8.5.9, 8.2.33, 8.3.3, and 8.4.24 security releases (Linux Compatible).
Due to the reserved status of this CVE and limited public disclosure, the precise confidentiality, integrity, and availability impacts are not yet confirmed. Given that the vulnerability affects PHP's GD image processing extension — which is commonly used for image creation, manipulation, and processing — potential impacts could include memory corruption, denial of service, or arbitrary code execution depending on the nature of the underlying libgd flaw. Organizations using PHP with the GD extension enabled should treat this as a medium-severity risk until further details are disclosed (Feedly).
The vulnerability has been addressed in PHP security releases, including PHP 8.5.9, 8.2.33, 8.3.3, and 8.4.24, via an upgrade of the libgd library bundled with the GD extension (Linux Compatible, Linux Compatible). Administrators should upgrade to the latest patched PHP version as soon as possible. Slackware Linux has also issued a security advisory (SSA-2026-211-01) addressing this issue for its users (Vulners/Slackware). As a temporary workaround, disabling the GD extension in php.ini (by commenting out or removing extension=gd) can reduce exposure if image processing functionality is not required.
The vulnerability has received limited but notable attention across security communities. The oss-security mailing list published a thread referencing CVE-2026-9672 in Q3 2026 (oss-sec), and social media activity was observed on Mastodon (Mastodon). Tenable has begun developing detection plugins for this CVE. Overall community reaction is measured, consistent with a medium-severity issue in a widely-used but well-maintained library.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."