The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Fedora has released PHP version 8.5.9, addressing various bugs, security issues, and improving functionality across multiple components, ensuring better stabil…
Debian Security Advisory DSA-6406-1 addresses multiple vulnerabilities in PHP 8.4 that could lead to denial of service, SQL injection, and arbitrary code execu…
Rocky Linux 9 has released a critical PHP update addressing multiple vulnerabilities, including remote code execution and denial of service, as detailed in the…
Several security issues were fixed in PHP.
Important: php:7.4 security update
Important: php:7.4 security update
Important: php:7.4 security update
PHP version 8.4.21 (07 May 2026) Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). (iliaal) Fixed bug GH-21478 (Forward …
MGASA-2026-0127 - Updated php packages fix security vulnerabilities
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable…
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable…
Two vulnerabilities were discovered in php-dompdf, a PHP library to convert HTML to PDF. CVE-2021-3838 php-dompdf is vulnerable to PHAR deserialization due to …
MGASA-2025-0330 - Updated php packages fix security vulnerabilities
PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn't work for nam…
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelector…
USN-7648-2 introduced a regression in PHP
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or …
Several security issues were fixed in PHP.
PGSQL: Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) SOAP: Fixed GHSA-453j-q27h-5p8x (NULL Pointer Der…
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the sec…
Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.
It was discovered that there was a remotely exploitable vulnerability in php-laravel-framework, a popular web application framework written in PHP.
Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States,…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…