CVE-2026-25237 | pear pearweb up to 1.32.x preg_replace /e executable regular expression error (GHSA-vhw6-hqh9-8r23 / Nessus ID 297928)
A vulnerability categorized as critical has been discovered in pear pearweb up to 1.32.x. Affected by this vulnerability is the function preg_replace. The manipulation of the argument /e results in executable regular expression error.
This vulnerability was named CVE-2026-25237. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.