Vulnerabilidades de PHP

Vulnerabilidades del intérprete PHP y de sus extensiones estándar. Ahora mismo seguimos 18 avisos, 14 con versión corregida publicada.

CVE-2025-1218 Baja 3.4 2026-09-25

PHP

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated…

Corregida en Debian 12 y Debian 13.

CVE-2025-14181 Media 6.5 2026-09-25

PHP

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised…

Corregida en Debian 12 y Debian 13.

CVE-2026-17545 Sin clasificar 2026-09-25

PHP

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path…

Sin parche todavía.

CVE-2026-6103 Media 4.3 2026-09-25

PHP

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF…

Corregida en Debian 12 y Debian 13.

CVE-2026-91765 Alta 7.5 2026-09-25

PHP

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements…

Corregida en Debian 12 y Debian 13.

CVE-2026-91766 Media 5.9 2026-09-25

PHP

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a…

Corregida en Debian 12 y Debian 13.

CVE-2026-91767 Media 6.5 2026-09-25

PHP

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are…

Corregida en Debian 12 y Debian 13.

CVE-2026-91768 Media 6.5 2026-09-25

PHP

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An…

Corregida en Debian 12 y Debian 13.

CVE-2026-91769 Media 4.3 2026-09-25

PHP

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once…

Corregida en Debian 12 y Debian 13.

CVE-2026-92842 Media 5.9 2026-09-25

PHP

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string…

Corregida en Debian 12 y Debian 13.

CVE-2026-93682 Media 5.8 2026-09-25

PHP

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location…

Corregida en Debian 12 y Debian 13.

CVE-2026-17543 Sin clasificar 2026-09-10

PHP

php8.1, php8.3, php8.5 vulnerabilities

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-84308 Media 6.3 2026-09-02

PHP

(phpseclib is a PHP secure communications library. Prior to 3.0.57 and ...)

Sin parche todavía.

CVE-2026-84361 Sin clasificar 2026-09-02

PHP

(Composer is a dependency Manager for the PHP language. From 1.0 until ...)

Sin parche todavía.

CVE-2026-9672 Sin clasificar 2026-07-31

PHP

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-17544 Sin clasificar 2026-07-30

PHP

Entradas proporcionadas por el atacante a bccomp() podrían provocar una escritura fuera de límites con corrupción de stack y heap en versiones de PHP desde 8.4.* antes de 8.4.24 y desde 8.5.* antes…

Sin parche todavía.

CVE-2026-7260 Media 5.5 2026-07-30

PHP

Los enlaces simbólicos circulares en archivos phar podrían provocar una recursión sin límite, agotando el stack de C y provocando el bloqueo del proceso PHP, en versiones de PHP desde 8.2.* antes de…

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-12184 Sin clasificar 2026-07-20

PHP

vulnerabilidades de php8.1, php8.3, php8.5

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.