Issue #2 ·
PHP Patches 11 CVEs, Next.js Ships 16.3.8 and PHP 8.6 Reaches RC: What to Patch, Plan and Watch (October 2, 2026)
This week in PHP, Laravel, React, TypeScript and Node.js: PHP's 11-CVE security release, Next.js 16.3.8, Laravel AI SDK 1.0, a compromised GitHub Action back online and $2 frontier coding models.

On this page
Welcome back to Web Programming. Every week I read the release notes, security advisories and changelogs for PHP, Laravel, React, TypeScript and Node.js and turn them into decisions: what to patch now, what to plan for, and what can wait. Every claim links to its primary source at the end.
A correction first. Issue #1 said PHP 8.6 RC1 would land on September 24. There was no RC1: a release script bumped the API version numbers at the wrong step, so the release managers skipped that tag. The first release candidate is called RC2 and shipped on September 24, and the later RCs moved up one number.
TL;DR: your checklist for this week
- PHP: upgrade to 8.5.11, 8.4.26, 8.3.35 or 8.2.34 (September 24). They fix 11 CVEs, including credentials leaking on HTTP redirects.
- Next.js: upgrade to 16.3.8 or 15.5.27 (September 30), and expect another release soon: a critical and a high fix are still waiting on an upstream dependency.
- laravel/ai and laravel/mcp: update both to 1.0.1 (an SSRF and an open redirect).
- GitHub Actions: remove or SHA-pin actions-cool/issues-helper and actions-cool/maintain-one-comment, and move any JavaScript action off Node 20: runners dropped it on September 23.
- Copilot Business or Enterprise admins: choose a default policy for new features before October 22.
- Calendar: PHP 8.6 RC3 on October 8, Node 24 to maintenance on October 20, Node 26 LTS on October 28, PHP 8.6 final on November 19.
1. Patch now: security
PHP. On September 24 PHP shipped security releases for every supported branch: 8.5.11, 8.4.26, 8.3.35 and 8.2.34, fixing 11 advisories. The ones most web apps should care about:
- CVE-2026-91766 (Moderate): the HTTP stream wrapper forwarded Authorization, Cookie and Proxy-Authorization headers unchanged when a redirect went to a different host or port, or from HTTPS to HTTP. If you send credentials through file_get_contents(), fopen() or a stream context, this one is yours: follow_location is on by default.
- CVE-2026-91768 (Moderate): PHP-FPM compared only the first 12 of 16 bytes of an IPv6 address, so listen.allowed_clients matched a whole /96 network. Unix sockets, IPv4-only setups and external firewalls aren't affected.
- CVE-2026-91767: a heap buffer overflow when OpenSSL matches a crafted wildcard name in a server certificate.
- CVE-2026-6103: an integer overflow in Phar's TAR parsing that allows entry injection.
The rest cover SOAP, mysqlnd, stream filters and Windows reserved device names.
Next.js. On September 30 Next.js released 16.3.8 (Active LTS) and 15.5.27 (Maintenance LTS), fixing seven vulnerabilities. The high-severity one, CVE-2026-94483, is a server-side request forgery in Image Optimization: an attacker-controlled, allow-listed remote URL can reach private IP ranges. If you don't configure images.remotePatterns, you're not affected. The medium ones cover cache poisoning of SSG and ISR pages, metadata image routes that ignore dynamicParams in webpack builds, and two 'use cache' leaks, one of which can expose Draft Mode content. The low one is worth knowing: the next dev server's MCP endpoint didn't check which website a request came from, so a malicious page you visit while developing could read your project's location, routes and logs.
Vercel also says a fix for one critical and one high vulnerability was postponed because of upstream dependency delays. Plan for another Next.js release soon.
Laravel. Laravel AI SDK 1.0.1 (September 29) fixes a moderate SSRF (GHSA-6qhr-3g93-pxhw): the Vercel AI SDK and AG-UI adapters fetched client-supplied file URLs without validating them. Only 1.0.0 is affected. Laravel MCP 1.0.1 and 0.9.6 (September 24) fix a low-severity open redirect in the OAuth flow (GHSA-mx2h-h55v-pm44). There are no new laravel/framework advisories this week.
2. Supply chain: a compromised GitHub Action came back
- Mini Shai-Hulud, again: actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled in May after the compromise, became available again on September 16 with their malicious tags still in place. Socket counts about 15,000 repositories depending on issues-helper alone. Its advice: remove them or pin a clean commit SHA from before May 18, rotate the secrets those workflows could reach since September 16, and look for runs that suddenly took minutes instead of seconds.
- MemTensor (September 23): compromised releases of @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) on npm and MemoryOS 2.0.34 on PyPI bundled a Go binary that searches $HOME for npm, PyPI, GitHub, AWS and SSH credentials. Pin to 0.1.20 and 2.0.33 or remove them, then rotate secrets.
- Node 20 is gone from GitHub Actions (September 23): JavaScript actions now run on Node 24, and the ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION opt-out no longer works. If you maintain an action, set runs.using to node24 and publish a release.
- Fewer long-lived tokens (September 30): npm trusted publishing can now manage dist-tags with short-lived OIDC credentials. It's an opt-in "Allow npm dist-tag" permission, so you can drop the token you kept just for tags.
- Money for maintainers (September 25): the OpenJS Foundation launched a Security Stewardship Program. Members contributing at least $100,000 a year (Socket and Aikido are first) fund bug bounties and maintainers' patch and release work, split 50/50.
My take: this week's pattern is attackers going where long-lived trust lives: tags, tokens and dev servers. Pin by SHA, prefer short-lived credentials, and don't assume localhost is private.
3. PHP 8.6: release candidate, frozen features, new session defaults
The schedule now: RC2 shipped September 24, then RC3 on October 8, RC4 on October 22, RC5 on November 5 and the final release on November 19. The hard feature freeze was September 22, so the feature list is set: partial function application, clamp(), a Time\Duration class, a new Io\Poll polling API, URI builders, and TLS session resumption and early data in OpenSSL streams.
The change most likely to bite is the session defaults:
- session.use_strict_mode is now 1.
- session.cookie_httponly is now 1, so JavaScript can no longer read the session cookie.
- session.cookie_samesite is now "Lax".
New deprecations include return inside finally, returning a value from __construct() or __destruct(), the third argument of define(), spl_object_hash() (use spl_object_id()), is_double(), is_long(), is_integer() and doubleval(), strcoll(), SORT_LOCALE_STRING, metaphone() and mbregex.
My take: add the 8.6 RC to your CI matrix now and search for session configuration and these functions. Most code bases will hit the session cookie change before anything else.
4. Laravel: AI SDK 1.0 and a busy September
Laravel AI SDK 1.0 (September 23) adds classification, Vercel AI and AG-UI streaming, tools that need human approval (Approvable), ToolSearch to load rarely used tools only when needed, a CodeExecution provider tool, and middleware that runs on every generation step. It breaks things too: tool calls and results move into a single steps column, token usage is now inputTokens and outputTokens, and the stream protocols changed. Laravel suggests the Boost MCP server's /upgrade-ai-sdk-v1 command for the upgrade. Go straight to 1.0.1.
Laravel 13.34.0 (September 29): worker crashes now count toward maxExceptions, jobs can be notified before they time out, JobProcessed carries the job's duration, queue:flush takes --queue, and Schema\Builder::getColumn() is new.
The September product update (October 2) adds per-pull-request preview environments, request metrics and managed database users to Laravel Cloud, runtime AI provider configuration for per-tenant keys, semantic and hybrid search for Scout's Typesense engine, Mercure broadcasting in Echo, and copyToDisk() and moveToDisk().
5. JavaScript and TypeScript: quieter, but plan for these
- Node.js: the calendar holds. Node 24 moves to maintenance on October 20 and Node 26 becomes active LTS on October 28.
- TypeScript 7.1: the release that brings back a stable API (Content Mapper, Emit and Language Service). Its beta, planned for October 6, is being pushed back about two weeks to allow more API testing. Vue, Svelte and Angular teams waiting on that API should stay on 6.0 a little longer.
- Vite+ 1.0 (September 28): an MIT-licensed vp command that ties Vite 8, Vitest, Rolldown, Oxlint and Oxfmt, tsdown and a monorepo task runner into one config. The team says it's not a replacement for Vite.
- React: no new release since 19.3 on September 9.
6. AI coding tools: frontier models got cheaper
- Claude Sonnet 5.5 (September 28): $2 per million input tokens and $10 per million output. Anthropic says it runs 30%+ faster than Sonnet 5 and costs up to 30% less for most work. It's generally available in GitHub Copilot.
- GPT-6.1 Sol (OpenAI DevDay, September 29): the same $2 and $10, pitched as "near-Astra intelligence for a fifth of the price." It's in the API as gpt-6.1-sol, in Codex, and in Copilot for Pro+, Max, Business and Enterprise.
- Agents are leaving the editor: Copilot computer use (public preview, October 1) drives desktop apps from the Copilot CLI and app on macOS and Windows, asking for approval before it controls an app. OpenAI's Agents API added computer use. JetBrains Air (early access, October 2) runs several agents in parallel inside JetBrains IDEs, with Codex, Gemini, Copilot, Claude Agent and Junie supported out of the box.
- Admins: from October 22, Copilot Business and Enterprise apply a default policy to every eligible feature, code review policy and MCP server setting you haven't configured. Pick Enabled, Disabled or "Let organizations decide" under AI Controls.
The full 2026 Stack Overflow Developer Survey results are due "in the next days." Its April pulse survey already showed AI agent use nearly doubling, to 59% from 31% in the 2025 survey.
My take: per-token prices fell, but agents spend far more tokens per task. Budget by task, not by token.
7. Careers: the numbers
- US jobs (October 2): payrolls grew by 29,000 in September and unemployment was 4.2%. July and August were revised down by a combined 60,000. Information and professional and business services showed little change.
- Layoffs (October 1): tech companies announced 10,799 cuts in September, up 77% from August, and 165,925 so far this year, 54% more than in 2025. AI was cited for 3,961 cuts in September and 120,136 this year, about 21% of all announced cuts.
- Postings: Indeed's US software development postings index was 77.32 on September 18 (February 2020 = 100), still about 23% below pre-pandemic levels.
Flat, not falling. The edge goes to engineers who can show they ship safely: patched, tested and with an eye on the supply chain.
One thing to do this week
Search your workflows for actions-cool/issues-helper and actions-cool/maintain-one-comment, then pin every third-party action to a full commit SHA. It takes ten minutes and closes the door this week's attack walked through.
That's issue #2. If it saved you time, follow Web Programming on LinkedIn or read every issue at webprg.com. And tell me in the comments: do you pin your GitHub Actions to commit SHAs?
Sources
- PHP release announcements, 2026
- PHP 8.5.11 ChangeLog
- PHP advisory: CVE-2026-91766 (HTTP redirect credential leak)
- PHP advisory: CVE-2026-91768 (PHP-FPM IPv6 ACL bypass)
- Why there is no PHP 8.6 RC1
- PHP 8.6 release schedule
- PHP 8.6 UPGRADING notes (RC2)
- Next.js September 2026 security release
- Laravel AI SDK advisory GHSA-6qhr-3g93-pxhw
- Laravel MCP advisory GHSA-mx2h-h55v-pm44
- Introducing Laravel AI SDK v1
- Laravel v13.34.0 release notes
- Laravel September product updates
- Socket: re-enabled GitHub Actions expose thousands to Mini Shai-Hulud
- Socket: MemTensor npm and PyPI compromise
- Node 20 is no longer available in GitHub Actions
- npm trusted publishing: opt-in dist-tag permissions
- OpenJS Foundation Security Stewardship Program
- Node.js release schedule
- TypeScript 7.1 iteration plan
- Announcing Vite+ 1.0
- Claude Sonnet 5.5
- Introducing GPT-6.1 Sol
- OpenAI DevDay 2026 recap
- Claude Sonnet 5.5 in GitHub Copilot
- GPT-6.1 Sol in GitHub Copilot
- GitHub Copilot can now interact with desktop apps
- Default enablement of Copilot features for Business and Enterprise
- JetBrains Air in IDEs (EAP)
- Stack Overflow: getting ready for the 2026 survey results
- BLS Employment Situation, September 2026
- Challenger, Gray & Christmas: September 2026 job cuts
- Indeed software development postings index (FRED)