Collected every two hours from specialised publications — each link leads to the original article.
MGASA-2025-0330 - Updated php packages fix security vulnerabilities
PHP version 8.4.16 (18 Dec 2025) Core: Sync all boost.context files with release 1.86.0. (mvorisek) Fixed bug GH-20435 (SensitiveParameter doesn't work for nam…
Researchers have detected active attacks from TellYouThePass ransomware that exploits the recently reported PHP flaw.…Recently Patched PHP Flaw Under Attack By…
The maintainers of the PHP programming language have issued an update regarding the security incident that came to light late last month , stating that the act…
The maintainers of the PHP programming language have issued an update regarding the security incident that came to light late last month, stating that the acto…
Unidentified attackers recently hacked the PHP Git server to inject the source code with a…Backdoor In PHP Source Code Discovered on Latest Hacking News
**PHP version 7.3.23** (01 Oct 2020) **Core:** * Fixed bug php#80048 (Bug php#69100 has not been fixed for Windows). (cmb) * Fixed bug php#80049 (Memleak when …
**PHP version 7.4.6** (14 May 2020) **Core:** * Fixed bug php#78434 (Generator yields no items after valid() call). (Nikita) * Fixed bug php#79477 (casting obj…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
A recently patched vulnerability (CVE-2019-11043) in PHP is being actively exploited by attackers to compromise NGINX web servers, threat intelligence firm Bad…
An update that solves six vulnerabilities and has one security fix can now be installed.
Important: git-lfs security update
In Horde Groupware, there has been an XSS via the Name field during creation of a new Resource. This could have been leveraged for remote code execution after …
**kronolith 4.2.29** * [mjr] Fix regresssion in event modification notifications (Bug #15022). ---- **kronolith 4.2.28** * [mjr] **SECURITY**: Don't leak priva…
**kronolith 4.2.29** * [mjr] Fix regresssion in event modification notifications (Bug #15022). ---- **kronolith 4.2.28** * [mjr] **SECURITY**: Don't leak priva…
Security researchers recently issued an update detailing how attackers are exploiting a PHP code execution vulnerability to spread TellYouThePass ransomware . …
Niels Dossche and Tim D'¼sterhus discovered that PHP's implementation of the SOAP HTTP Digest authentication did not check for failures, which may result in a …
It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…
It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…
Over the next couple of weeks and months, LinuxSecurity editors and contributors will be writing a series on Linux Web Server Security. This week, we're summar…
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…