Collected every two hours from specialised publications — each link leads to the original article.
Oracle Linux has released updates for PHP 8.4.24 addressing CVEs 2026-17543 and 2026-17544, with new RPMs for x86_64 and aarch64 architectures available via th…
Fedora 44 has released an update for php-phpseclib to version 2.0.55, addressing CVE-2026-44167, which involves a denial of service due to untrusted ASN.1 file…
An update for Mageia 10 fixes an import error that caused the php[8.4,8.5]-imap package to lack SSL support, which is now deprecated and should be replaced.
A security and enhancement update for PHP 8.2, addressing a denial of service vulnerability and various bug fixes, is now available for Rocky Linux 9 users.
Oracle Linux issued a security advisory with updated RPM packages for PHP and related modules, addressing various vulnerabilities and introducing version updat…
Mageia 10 has released an update to php-fpdf version 1.9.0, which resolves deprecated warnings in PHP 8.5 and a bug linked to PDF creation dates.
Oracle Linux 8 has released security updates including PHP 8.2.32 and libzip 1.7.3, addressing CVE-2026-14355, with multiple related packages uploaded to the U…
Oracle Linux Security Advisory ELSA-2026-48170 announces updated RPM packages for PHP version 8.3.32 for x86_64 and aarch64 architectures, addressing vulnerabi…
Debian Security Advisory DSA-6406-1 addresses multiple vulnerabilities in PHP 8.4 that could lead to denial of service, SQL injection, and arbitrary code execu…
Important: php:7.4 security update
Important: php:7.4 security update
MGASA-2026-0127 - Updated php packages fix security vulnerabilities
USN-7648-2 introduced a regression in PHP
Several security issues were fixed in PHP.
Several security issues were fixed in PHP.
Arbitrary file include in Carbon::setLocale has been fixed in Carbon, a PHP API extension for DateTime. For Debian 11 bullseye, this problem has been fixed in …
Several security issues were fixed in PHP.
Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.
Version 6.8.0 (2024-12-23) Requires PHP 7.1+ and curl extension. Escape error message. Use strict time-constant function to compare TCPDF-tag hashes. Add K_CUR…
Version 6.8.0 (2024-12-23) Requires PHP 7.1+ and curl extension. Escape error message. Use strict time-constant function to compare TCPDF-tag hashes. Add K_CUR…
It was discovered that there was a remotely exploitable vulnerability in php-laravel-framework, a popular web application framework written in PHP.
Moderate: php:8.2 security update
Moderate: php:8.1 security update
USN-7157-1 introduced a regression in PHP.