A security vulnerability known as HTTP request smuggling has been identified in the Erlang OTP inets httpd module, a component used to run web servers. This flaw stems from how the server handles duplicate "Content-Length" headers, which specify the size of data included in a web request: the server uses the first header of this type it receives, ...
Continue reading
A security flaw exists in specific PHP versions (8.4.* older than 8.4.21 and 8.5.* older than 8.5.6) that impacts the mbstring extension, a tool used to handle text encoding conversions for websites. The issue is triggered when a specially crafted encoding name containing a hidden embedded NUL byte is passed to affected mbstring functions.When ...
Continue reading
A security issue has been identified in specific older versions of PHP, the software that powers many websites. This affects PHP 8.2 versions older than 8.2.31, 8.3 versions older than 8.3.31, 8.4 versions older than 8.4.21, and 8.5 versions older than 8.5.6.
The vulnerability applies to sites that use PHP’s SOAP feature (a tool for connecting ...
Continue reading
A security vulnerability has been identified in specific versions of PHP, the software that powers most dynamic websites and web applications. The flaw exists in the SOAP extension, a component used to handle data exchanges for certain web services, and impacts PHP 8.2 versions older than 8.2.31, PHP 8.3 versions older than 8.3.31, PHP 8.4 ...
Continue reading