PHP Dev
damienseguy's profile
Damien seguy@damienseguy•May 11
21.2K
Exakat's profile
Post cover image

PHP 8.5.6 / 8.4.21 / 8.3.31 / 8.2.31: What's Actually in the May Security Patch

From blog.kalfaoglu.net•May 11•4m read time

PHP released simultaneous security updates on May 7, 2026 for all four supported branches (8.5.6, 8.4.21, 8.3.31, 8.2.31). Key fixes include: CVE-2026-6735, an XSS vulnerability in the PHP-FPM status page that reflects unsanitized URIs; three SOAP extension memory bugs (use-after-free, stale pointer, broken NULL check) affecting SOAP_PERSISTENCE_SESSION; two MBString memory issues (null pointer dereference and out-of-bounds access); and standard library fixes for integer overflow in metaphone() and an unsigned-char bug. Additional patches cover DOM extension XML issues and a PDO_Firebird SQL injection via NUL bytes. All PHP 8.2–8.5 versions prior to the patched releases are affected; PHP 8.1 and older no longer receive security updates.

Sort:

damienseguy's user avatar
Damien seguy
@damienseguy
Joined Oct 25. 2023
21.2K
Exakat's profile

Exakat

Verified

PHP developer passionate about deep language knowledge, testing, static analysis, and sustainable it

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard