PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 4 009
CVE-2026-17544
Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.
CVE-2026-17543
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
GHSA-vc5h-9ppw-p5f3
Stack overflow in phar with circular symlinks
GHSA-x692-q9x7-8c3f
Out-of-bounds write in bccomp() via crafted operand and scale
GHSA-7qpv-r5mr-78m4
SQL injection in ext-pgsql via E'...' backslash breakout
ELSA-2026-48170
ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)
SUSE-SU-2026:3165-1
Security update for php7
ELSA-2026-40416
ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-17544 Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9. | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-17543 Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. | CVSS3: 7.4 | 0% Низкий | около 2 месяцев назад | |
GHSA-vc5h-9ppw-p5f3 Stack overflow in phar with circular symlinks | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-x692-q9x7-8c3f Out-of-bounds write in bccomp() via crafted operand and scale | 0% Низкий | около 2 месяцев назад | ||
GHSA-7qpv-r5mr-78m4 SQL injection in ext-pgsql via E'...' backslash breakout | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-48170 ELSA-2026-48170: php security, bug fix, and enhancement update (LOW) | 0% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:3165-1 Security update for php7 | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-40416 ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW) | 0% Низкий | около 2 месяцев назад | ||
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ... | CVSS3: 5.6 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу