The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the sec…
Several security issues were fixed in PHP.
Arbitrary file include in Carbon::setLocale has been fixed in Carbon, a PHP API extension for DateTime. For Debian 11 bullseye, this problem has been fixed in …
Several security issues were fixed in PHP.
Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.
Version 6.8.0 (2024-12-23) Requires PHP 7.1+ and curl extension. Escape error message. Use strict time-constant function to compare TCPDF-tag hashes. Add K_CUR…
Version 6.8.0 (2024-12-23) Requires PHP 7.1+ and curl extension. Escape error message. Use strict time-constant function to compare TCPDF-tag hashes. Add K_CUR…
It was discovered that there was a remotely exploitable vulnerability in php-laravel-framework, a popular web application framework written in PHP.
Moderate: php:8.2 security update
Moderate: php:8.1 security update
Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States,…
USN-7157-1 introduced a regression in PHP.
Several security issues were fixed in PHP.
PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug G…
New php packages are available for Slackware 15.0 and -current to fix security issues.
bartlett/php-compatinfo-db 6.12.0 - 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
bartlett/php-compatinfo-db 6.12.0 - 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support
Several security issues were fixed in PHP.
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection f…
It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform.
It was discovered that there was an arbitrary object deserialization vulnerability in php-horde-turba, an address book component for the Horde groupware suite.
PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fi…