PatchSiren cyber security CVE debrief
CVE-2016-10159 PHP CVE debrief
CVE-2016-10159 is a PHP PHAR parsing vulnerability that can be triggered by a truncated manifest entry in a PHAR archive. The result is a denial of service through excessive memory consumption or an application crash; the NVD CVSS vector rates this as network-exploitable, unauthenticated, and availability-only.
- Vendor
- PHP
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-24
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-24
- Advisory updated
- 2026-05-13
Who should care
Teams running PHP-based web applications, hosting platforms, container images, Linux distributions that ship PHP, and anyone who accepts or processes user-supplied PHAR archives should care most.
Technical summary
According to the CVE description and NVD record, an integer overflow in phar_parse_pharfile() in ext/phar/phar.c can occur while parsing a truncated manifest entry inside a PHAR archive. NVD lists affected PHP versions as before 5.6.30 and 7.0.x before 7.0.15, with additional vulnerable CPE coverage also present in the record. The practical impact is denial of service only: memory consumption or crash, with no CVE evidence here for confidentiality or integrity impact.
Defensive priority
High for exposed PHP services that may ingest untrusted archives or content. The issue is remotely reachable and requires no privileges or user interaction per the CVSS vector, so patching should be prioritized with normal emergency maintenance for internet-facing PHP deployments.
Recommended defensive actions
- Upgrade PHP to a fixed release at or above the vendor-patched versions noted in the PHP 5 and PHP 7 changelogs.
- Apply your distribution or platform vendor updates if you consume packaged PHP builds rather than upstream releases.
- Review any application paths that accept or unpack PHAR archives from untrusted sources and limit that input where possible.
- Confirm whether your deployed PHP build falls within the affected version ranges listed by NVD before and after remediation.
- Track downstream advisories from your OS or hosting vendor to ensure the packaged PHP runtime is fully updated.
Evidence notes
This debrief is based only on the supplied CVE record and linked official/vendor references. The CVE description states an integer overflow in phar_parse_pharfile() can be triggered by a truncated manifest entry in a PHAR archive, causing denial of service via memory consumption or crash. NVD provides the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and lists affected PHP ranges through 5.6.29 and 7.0.x before 7.0.15, plus an additional PHP 7.1.0 CPE criterion in the record. The CVE was published on 2017-01-24 and the NVD record was modified on 2026-05-13; it is not marked as a KEV item in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10159 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10159
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10159 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10159
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2018:1296
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.