PHP 8.0

Fin de soporte

PHP 8.0 es una versión estable, publicada el 26 de noviembre de 2020. Dejó de recibir parches de seguridad el 26 de noviembre de 2023. La última versión puntual publicada es la 8.0.30, del 3 de agosto de 2023.

Avisos de seguridad

Seguimos 18 avisos que afectan a PHP. Son los avisos del producto: no están filtrados por versión.

CVE-2025-1218 Baja 3.4 2026-09-25

PHP

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated…

Corregida en Debian 12 y Debian 13.

CVE-2025-14181 Media 6.5 2026-09-25

PHP

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised…

Corregida en Debian 12 y Debian 13.

CVE-2026-17545 Sin clasificar 2026-09-25

PHP

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path…

Sin parche todavía.

CVE-2026-6103 Media 4.3 2026-09-25

PHP

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF…

Corregida en Debian 12 y Debian 13.

CVE-2026-91765 Alta 7.5 2026-09-25

PHP

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements…

Corregida en Debian 12 y Debian 13.

CVE-2026-91766 Media 5.9 2026-09-25

PHP

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a…

Corregida en Debian 12 y Debian 13.

Ver los 18 avisos de PHP

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.

Si lo instalaste desde tu distribución, esta fecha no es la tuya

Estas son las fechas del proyecto original. Debian, Ubuntu y RHEL congelan una versión al publicar cada release y le retroportan los parches de seguridad durante todo el ciclo de la distribución, así que un paquete que aquí figura fuera de soporte puede seguir recibiendo correcciones por la vía de tu distribución. Lo que manda entonces es el calendario de la distribución.