CVE-2025-14177

Information Leak of Memory in getimagesize

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.


We have discovered 2,590,163 live websites that are affected by CVE-2025-14177.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,590,163 live websites (35% of PHP install base)
Vulnerable Versions
  • from 8.1 through 8.1.34
  • from 8.2 through 8.2.30
  • from 8.3 through 8.3.29
  • from 8.4 through 8.4.16
  • from 8.5 through 8.5.1
Vulnerable Versions Count110 versions ( 22% of all versions)


Common Weakness Enumeration

CWE-125 Out-of-bounds Read



Details

  • Published - Dec 27, 2025
  • Updated - Dec 29, 2025

Credits

  • Nikita Sveshnikov (Positive Technologies) (reporter)

Website Distribution by Country

Number of websites using CVE-2025-14177
United States532,748 websites



Germany516,403 websites
France181,393 websites
Netherlands153,924 websites
Cyprus122,076 websites
GB120,119 websites
Russia93,224 websites
Sweden70,184 websites
Spain67,063 websites
Japan66,406 websites

Website Distribution by TLD

Number of websites using CVE-2025-14177
.com942,623 websites
.de326,659 websites
.nl147,679 websites
.org105,503 websites
.fr78,491 websites
.ru77,736 websites
.co.uk76,455 websites
.net70,431 websites
.se55,780 websites
.com.br50,784 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14177

Top websites that are affected by CVE-2025-14177. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States***
******.com United States***
**************.de Germany***
***.******.com United States***
********.com United States***
******.org United States***
************.com United States***
*********.space United States***
********.info United States***
********.org United States***
See full domain list

FAQ

CVE-2025-14177 is Out-of-bounds Read in PHP
A total of 2,590,163 websites have been identified as vulnerable to CVE-2025-14177, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2025-14177 vulnerability.
PHP versions up to 8.5.1 are vulnerable to CVE-2025-14177.
CVE-2025-14177 is resolved in version 8.5.1 of PHP.