The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Critical bugs closed: - Use-of-uninitialized-value in exif [1] - mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full [2] - get_headers(…
A remote code execution vulnerability was discovered in the Form API component of the Horde Application Framework. An authenticated remote attacker could use t…
**Horde_Form 2.0.20** * [mjr] SECURITY: Prevent ability to specify temporary filename (CVE-2020-8866, Reported By: Andrea Cardaci working with Trend Micro Zero…
An update that fixes 6 vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
**Horde_Data 2.1.5** * [jan] Fix Remote Code Execution vulnerability (CVE-2020-8518, Reported by: Andrea Cardaci/SSD).
An update that fixes four vulnerabilities is now available.
## 2.1.1 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 ## 2.1.0 Backports changes from 3.0 branch
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
## 2.1.1 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 ## 2.1.0 Backports changes from 3.0 branch
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3287
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3286
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in in denial of service, informati…
Release 1.6.19 Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294) Security: Fix CSS declaration smugglin…
Fedora released an update for php-pear-PHP-CodeSniffer (4.0.4) with security fixes and enhancements, emphasizing the need for users to promptly update due to v…
An update for PHP 8.4 on Rocky Linux 10 addresses a denial of service vulnerability and includes various bug fixes and enhancements, with a CVSS base score of …
Debian has released a security advisory for PHP 8.2, addressing vulnerabilities that could lead to denial of service and SQL injection. Users are urged to upgr…
Mageia 10 has released updates for php 8.4 to address multiple security vulnerabilities, as identified by CVEs CVE-2026-17544, CVE-2026-9672, CVE-2026-17543, a…
Oracle Linux 10 has updated RPM packages for PHP 8.4.23, addressing CVE-2026-14355, and is available for both x86_64 and aarch64 architectures through the Unbr…
Release 1.7.2 Add HEAD request handler to the static.php Fix so the oauth_password_claim claim is retrieved via token or userinfo request (#9631) Fix bug where…
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …