<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:03:18 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:22649 — Important: php8.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:22649</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: php8.4, AlmaLinux:10: php8.4-bcmath, AlmaLinux:10: php8.4-cli, AlmaLinux:10: php8.4-common, AlmaLinux:10: php8.4-dba, AlmaLinux:10: php8.4-dbg, AlmaLinux:10: php8.4-devel, AlmaLinux:10: php8.4-embedded, AlmaLinux:10: php8.4-enchant, AlmaLinux:10: php8.4-ffi and 15 more&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
  * PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
  * php: NULL pointer dereference in SOAP apache:Map decoder with missing &amp;lt;value&amp;gt; (CVE-2026-7262)
  * php: signed integer overflow in metaphone() (CVE-2026-7568)
  * php: denial of service via DOMNode::C14N() (CVE-2026-7263)
  * php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: php8.4, AlmaLinux:10: php8.4-bcmath, AlmaLinux:10: php8.4-cli, AlmaLinux:10: php8.4-common, AlmaLinux:10: php8.4-dba, AlmaLinux:10: php8.4-dbg, AlmaLinux:10: php8.4-devel, AlmaLinux:10: php8.4-embedded, AlmaLinux:10: php8.4-enchant, AlmaLinux:10: php8.4-ffi and 15 more&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)
  * PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)
  * php: NULL pointer dereference in SOAP apache:Map decoder with missing &amp;lt;value&amp;gt; (CVE-2026-7262)
  * php: signed integer overflow in metaphone() (CVE-2026-7568)
  * php: denial of service via DOMNode::C14N() (CVE-2026-7263)
  * php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:22649</guid>
    </item>
    <item>
      <title>bdu:2026-13295</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13295</link>
      <description>bdu:2026-13295</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13295</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2026-6104 — CVE-2026-6104 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-6104</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-6104</guid>
    </item>
    <item>
      <title>BIT-libphp-2026-6104 — Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libphp-2026-6104</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libphp-2026-6104</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0553 — De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0553</link>
      <description>certfr-2026-avi-0553</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0553</guid>
    </item>
    <item>
      <title>EUVD-2026-337174</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337174</link>
      <description>EUVD-2026-337174</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337174</guid>
    </item>
    <item>
      <title>fkie_cve-2026-6104</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6104</link>
      <description>&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-6104</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10747-1 — php8-8.5.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10747-1</link>
      <description>&lt;p&gt;php8-8.5.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php8-8.5.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10747-1</guid>
    </item>
    <item>
      <title>RLSA-2026:22649 — Important: php8.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:22649</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: php8.4&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)&lt;/p&gt;
&lt;p&gt;* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)&lt;/p&gt;
&lt;p&gt;* php: NULL pointer dereference in SOAP apache:Map decoder with missing &amp;lt;value&amp;gt; (CVE-2026-7262)&lt;/p&gt;
&lt;p&gt;* php: signed integer overflow in metaphone() (CVE-2026-7568)&lt;/p&gt;
&lt;p&gt;* php: denial of service via DOMNode::C14N() (CVE-2026-7263)&lt;/p&gt;
&lt;p&gt;* php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: php8.4&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions (CVE-2026-7258)&lt;/p&gt;
&lt;p&gt;* PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation (CVE-2026-6735)&lt;/p&gt;
&lt;p&gt;* php: NULL pointer dereference in SOAP apache:Map decoder with missing &amp;lt;value&amp;gt; (CVE-2026-7262)&lt;/p&gt;
&lt;p&gt;* php: signed integer overflow in metaphone() (CVE-2026-7568)&lt;/p&gt;
&lt;p&gt;* php: denial of service via DOMNode::C14N() (CVE-2026-7263)&lt;/p&gt;
&lt;p&gt;* php: global buffer over-read in mb_convert_encoding() with attacker-supplied encoding (CVE-2026-6104)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:22649</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21612-1 — Security update for php8</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21612-1</link>
      <description>&lt;p&gt;Security update for php8&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php8&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21612-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-6104</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6104</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: php8.4, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: php8.4, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6104</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1433 — PHP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1433</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um beliebigen Programmcode auszuführen, SQL-Injection- oder Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um beliebigen Programmcode auszuführen, SQL-Injection- oder Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1433</guid>
    </item>
  </channel>
</rss>
