Announcements

CVE-2026-6104 (matched: php)

  • 26th July 2026
A security vulnerability has been found in specific recent versions of PHP, the software that powers most dynamic websites. The affected versions are 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6. The flaw is triggered when a specially crafted input containing a hidden null byte is sent to PHP's character encoding tools, ...
Continue reading

CVE-2026-7261 (matched: php)

  • 26th July 2026
A security vulnerability, tracked as CVE-2026-7261, exists in older versions of PHP, the software many websites use to run dynamic features. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The flaw impacts sites that use PHP's SOAP ...
Continue reading

CVE-2026-6722 (matched: php)

  • 26th July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading

CVE-2025-14179 (matched: php)

  • 26th July 2026
A security flaw has been identified in specific older versions of PHP, the core software that runs most dynamic websites, that affects sites using the PDO Firebird tool to connect to Firebird databases.The issue occurs when the tool builds database queries from user-submitted input, such as form entries. If the input contains a hidden NUL ...
Continue reading