Web Programming

Patch nowPHP & Laravel

PHP 8.5.11, 8.4.26, 8.3.35 and 8.2.34 fix 11 security advisories

Issue #2

On September 24 PHP shipped security releases for every supported branch, including a fix for credentials leaking on HTTP redirects.

Karlen TriminoSenior Full-Stack Engineer

Leer en español
Photo: panumas nikhomkhai / Pexels

What to do

Upgrade to 8.5.11, 8.4.26, 8.3.35 or 8.2.34.

Key facts

Fixed in
8.2.34, 8.3.35, 8.4.26, 8.5.11
Advisory IDs
CVE-2026-91766, CVE-2026-91768, CVE-2026-91767, CVE-2026-6103

On September 24 PHP shipped security releases for every supported branch: 8.5.11, 8.4.26, 8.3.35 and 8.2.34, fixing 11 advisories. The ones most web apps should care about:

  • CVE-2026-91766 (Moderate): the HTTP stream wrapper forwarded Authorization, Cookie and Proxy-Authorization headers unchanged when a redirect went to a different host or port, or from HTTPS to HTTP. If you send credentials through file_get_contents(), fopen() or a stream context, this one is yours: follow_location is on by default.
  • CVE-2026-91768 (Moderate): PHP-FPM compared only the first 12 of 16 bytes of an IPv6 address, so listen.allowed_clients matched a whole /96 network. Unix sockets, IPv4-only setups and external firewalls aren't affected.
  • CVE-2026-91767: a heap buffer overflow when OpenSSL matches a crafted wildcard name in a server certificate.
  • CVE-2026-6103: an integer overflow in Phar's TAR parsing that allows entry injection.

The rest cover SOAP, mysqlnd, stream filters and Windows reserved device names.

Sources