A flaw in PHP’s PostgreSQL driver shows how emulated prepares can turn a routine parameter path into a process-level denial of service.