Vulnerability record · CVE-2022-31626 · published 16 June 2022
CVE-2022-31626: PHP pdo_mysql/mysqlnd buffer overflow via oversized password
Php · Php
PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7 contain a classic buffer overflow in the pdo_mysql extension when using the mysqlnd driver. If an application lets a third party supply the database host and password, a password of excessive length overflows the buffer and can lead to remote code execution.
Description
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS, but exploitation requires the application to accept attacker-controlled host and password values.
What it is
PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7 contain a classic buffer overflow in the pdo_mysql extension when using the mysqlnd driver. If an application lets a third party supply the database host and password, a password of excessive length overflows the buffer and can lead to remote code execution.
Impact
An attacker who controls the supplied host and password can trigger memory corruption in the PHP process, potentially achieving remote code execution with the privileges of that process.
Attack surface
Reached over the network through the application's database connection path when user-controlled host and password values are passed to pdo_mysql with mysqlnd. The CVSS vector requires low privileges and no user interaction.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.58123 (99th percentile) and the vendor bug reference is tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Upgrade PHP to 7.4.30, 8.0.20, 8.1.7 or later, or apply the vendor patch referenced in the PHP bug report.
- Update distribution packages (Debian DSA-5179, Fedora, Gentoo GLSA 202209-20) to the fixed versions.
- Do not allow untrusted users to supply the database host or password used by pdo_mysql; enforce server-side allowlists and length limits.
- If immediate patching is not possible, restrict network access to the PHP application and monitor for abnormal database connection parameters.
Detection
- Search application and web logs for unusually long password values or user-controlled host parameters passed to database connection routines.
- Monitor PHP-FPM/Apache process crashes or memory corruption signals that coincide with database connection attempts.
- Audit code paths where request data flows into PDO MySQL DSN or password arguments, especially multi-tenant or user-configurable connection settings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-31626 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31626), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.