Researchers disclosed two vulnerabilities in PHP’s PDO database layer that affect the Firebird and PostgreSQL drivers, showing how low-level driver behavior can bypass application safeguards. The more severe issue, tracked as CVE-2026-25289 in one report and previously referenced as CVE-2025-14179, affects pdo_firebird and can lead to SQL injection when NUL bytes inside quoted input are mishandled during SQL statement reconstruction, potentially dropping a closing quote and allowing attacker-controlled SQL to execute.
A second flaw, CVE-2026-25290 and previously referenced as CVE-2025-14180, affects PDO quoting with pdo_pgsql when emulated prepared statements are enabled. Invalid multibyte input can cause PostgreSQL escaping to return NULL, which PDO then dereferences, crashing PHP processes and creating a denial-of-service condition. The bugs were identified by PT SWARM researchers Aleksey Solovev and Nikita Sveshnikov, and patched PHP releases are available; organizations running older versions are exposed until they upgrade and should avoid unnecessary emulated prepares where possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
PHP released fixes for the two PDO driver vulnerabilities affecting Firebird and PostgreSQL. The patched releases address the SQL injection issue in pdo_firebird and the NULL dereference crash issue in pdo_pgsql.
PT SWARM researchers Aleksey Solovev and Nikita Sveshnikov identified a SQL injection flaw in pdo_firebird and a denial-of-service flaw in pdo_pgsql during an audit of PDO and its dependent client libraries.
On 2026-07-07, Cyber Security News reported the newly disclosed vulnerabilities affecting PHP's PDO Firebird and PostgreSQL drivers, highlighting the risks to unpatched deployments and summarizing the released fixes.
On 2026-07-06, Positive Technologies published PT SWARM's technical analysis detailing the pdo_firebird NUL-byte SQL injection issue and the pdo_pgsql NULL pointer dereference issue, along with exploitation mechanics and mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceswarm.ptsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.