Vulnerability record · CVE-2014-8142 · published 20 December 2014
CVE-2014-8142: PHP unserialize use-after-free via duplicate object keys
Php · Php
PHP's process_nested_data function in ext/standard/var_unserializer.re mishandles duplicate keys within serialized object properties, causing a use-after-free. This affects PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4, and a crafted unserialize call can lead to arbitrary code execution.
Description
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit material and very high EPSS, though not in KEV.
What it is
PHP's process_nested_data function in ext/standard/var_unserializer.re mishandles duplicate keys within serialized object properties, causing a use-after-free. This affects PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4, and a crafted unserialize call can lead to arbitrary code execution.
Impact
An attacker can corrupt memory and potentially execute arbitrary code in the context of the PHP process. This can lead to full compromise of the web application or server depending on privileges.
Attack surface
Reachable remotely over the network with no authentication required (AV:N/Au:N) wherever untrusted input is passed to unserialize(). No user interaction is indicated by the vector.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.53166, 98.9th percentile) and a reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade PHP to 5.4.36, 5.5.20, 5.6.4 or later, or apply the vendor commit fix.
- Apply distribution security updates (Debian DSA-3117, Red Hat RHSA-2015-1053/1066/1135, openSUSE, Gentoo GLSA 201503-03).
- Avoid passing untrusted input to unserialize(); use json_decode or other safe formats instead.
- If unserialize must be used, restrict it with allowed_classes and validate/sanitize input before deserialization.
Detection
- Search application and web logs for requests containing serialized object payloads with duplicate property keys.
- Monitor for PHP process crashes or abnormal memory errors correlated with unserialize calls.
- Use WAF or runtime rules to flag or block untrusted serialized data reaching unserialize().
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-8142 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-8142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.