The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform.
It was discovered that there was an arbitrary object deserialization vulnerability in php-horde-turba, an address book component for the Horde groupware suite.
PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…
Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.
Multiple threat actors have been observed exploiting a recently disclosed security flaw in PHP to deliver remote access trojans, cryptocurrency miners, and dis…
This update ships the latest version of php 8.2. It brings fixed security issues and the usual bug fixes. Vulnerability: A code logic error, filtering function…
Researchers have detected active attacks from TellYouThePass ransomware that exploits the recently reported PHP flaw.…Recently Patched PHP Flaw Under Attack By…
PHP version 8.2.20 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass …
Researchers have discovered a serious remote code execution vulnerability affecting PHP installations. As observed, this…Upgrade Your PHP Installations for A C…
PHP version 8.3.8 (06 Jun 2024) CGI: Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) Fixed bug GHSA-3qgc-jrrr-25jv (Bypass o…
Details have emerged about a new critical security flaw impacting PHP that could be exploited to achieve remote code execution under certain circumstances.The …
An header injection issue was fixed in php-nyholm-psr7.
Several header injection issues were fixed in php-guzzlehttp-psr7.
The container bci/php-fpm was updated. The following patches have been included in this update:
The container bci/php was updated. The following patches have been included in this update:
The container bci/php-apache was updated. The following patches have been included in this update:
It was discovered that php-phpseclib, a PHP library for arbitrary-precision integer arithmetic, was vulnerable to the so-called Terrapin Attack.
The container bci/php-fpm was updated. The following patches have been included in this update:
The container bci/php was updated. The following patches have been included in this update:
The container bci/php-fpm was updated. The following patches have been included in this update: