Fin de soporte de PHP

Seguimos 6 versiones de PHP: 4 con soporte vigente y 2 fuera de soporte. La más reciente es la 8.5, publicada el 20 de noviembre de 2025. La primera en quedarse sin parches es la 8.2, el 31 de diciembre de 2026.

Actualizado el 2026-09-30.

Versiones

Versión Lanzamiento Fin de soporte Soporte extendido Estado
8.5 20 de noviembre de 2025 31 de diciembre de 2029 — Soportada
8.4 21 de noviembre de 2024 31 de diciembre de 2028 — Soportada
8.3 23 de noviembre de 2023 31 de diciembre de 2027 — Soportada
8.2 8 de diciembre de 2022 31 de diciembre de 2026 — Menos de seis meses
8.1 25 de noviembre de 2021 31 de diciembre de 2025 — Fin de soporte
8.0 26 de noviembre de 2020 26 de noviembre de 2023 — Fin de soporte

Avisos de seguridad

Seguimos 18 avisos que afectan a PHP.

CVE-2025-1218 Baja 3.4 2026-09-25

PHP

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated…

Corregida en Debian 12 y Debian 13.

CVE-2025-14181 Media 6.5 2026-09-25

PHP

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised…

Corregida en Debian 12 y Debian 13.

CVE-2026-17545 Sin clasificar 2026-09-25

PHP

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path…

Sin parche todavía.

CVE-2026-6103 Media 4.3 2026-09-25

PHP

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF…

Corregida en Debian 12 y Debian 13.

CVE-2026-91765 Alta 7.5 2026-09-25

PHP

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements…

Corregida en Debian 12 y Debian 13.

CVE-2026-91766 Media 5.9 2026-09-25

PHP

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a…

Corregida en Debian 12 y Debian 13.

Ver los 18 avisos de PHP

¿Te toca migrar?

Saber la fecha es la parte fácil. Planificar el salto de versión sin cortar el servicio es lo que hacemos.

Ver servicios

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.

Si lo instalaste desde tu distribución, esta fecha no es la tuya

Estas son las fechas del proyecto original. Debian, Ubuntu y RHEL congelan una versión al publicar cada release y le retroportan los parches de seguridad durante todo el ciclo de la distribución, así que un paquete que aquí figura fuera de soporte puede seguir recibiendo correcciones por la vía de tu distribución. Lo que manda entonces es el calendario de la distribución.