Intel

AIKIDO-2026-10175

hisamu/php-xbase is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 16, 2026

42

Medium Risk

This Affects:

PHPhisamu/php-xbase
1.3.0 - 2.3.0
Fixed in 2.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not properly validate memo field lengths when processing corrupted FPT files, allowing the parser to attempt excessive memory allocation that may lead to fatal errors or denial of service. An attacker could exploit this by supplying a specially crafted or malformed FPT file with an abnormally large memo length value, causing the application to allocate massive memory and crash or exhaust system resources during file processing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hisamu/php-xbase is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.3.0 - 2.3.0.

How to fix this

Upgrade the hisamu/php-xbase library to the patch version.