PHP Group PHP
12 known vulnerabilities in PHP Group PHP, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2024-4577 CVSS 9.8 critical · actively exploited PHP-CGI OS Command Injection Vulnerability
Latest vulnerabilities
- CVE-2026-92842 CVSS 5.9 medium The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars…
- CVE-2026-91768 CVSS 6.5 medium The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients…
- CVE-2026-91769 CVSS 4.3 medium PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to…
- CVE-2026-91767 CVSS 6.5 medium php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server…
- CVE-2026-91766 CVSS 5.9 medium When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers…
- CVE-2026-91765 CVSS 7.5 high cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a…
- CVE-2026-6103 CVSS 4.3 medium phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide…
- CVE-2026-17545 CVSS 6.9 medium On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9…
- CVE-2025-1218 CVSS 3.4 low The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A…
- CVE-2025-14181 CVSS 6.5 medium The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour…
- CVE-2026-93682 CVSS 5.8 medium When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads…
- CVE-2024-4577 CVSS 9.8 critical · actively exploited PHP-CGI OS Command Injection Vulnerability