Skip to content
PHP News
Search

PHP version support

PHP 8.2 end of life and support status

Security fixes only. Ends in 99 days (December 31, 2026).

Key dates

Released
December 8, 2022
Active support ended
December 31, 2024
Security support ends (end of life)
December 31, 2026
Latest release
8.2.33, July 30, 2026

Security fixes in PHP 8.2

43 security advisories fixed on this branch, newest first, with the release that fixed each one. Covers the advisories php-src has published on GitHub, which started in February 2023.

  • medium CVE-2026-7260 Fixed in 8.2.33, Jul 30, 2026

    Stack overflow in phar with circular symlinks

  • high CVE-2026-17543 Fixed in 8.2.33, Jul 30, 2026

    SQL injection in ext-pgsql via E'...' backslash breakout

  • medium CVE-2026-14355 Fixed in 8.2.32, Jul 2, 2026

    ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD

  • medium CVE-2026-7262 Fixed in 8.2.31, May 7, 2026

    NULL pointer dereference in SOAP apache:Map decoder with missing <value>

  • medium CVE-2026-7261 Fixed in 8.2.31, May 7, 2026

    SoapServer session-persisted object use-after-free via SOAP header fault

  • low CVE-2026-7259 Fixed in 8.2.31, May 7, 2026

    Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

  • medium CVE-2026-6735 Fixed in 8.2.31, May 7, 2026

    XSS within PHP-FPM status endpoint

  • high CVE-2026-6722 Fixed in 8.2.31, May 7, 2026

    Use-After-Free in SOAP using Apache map with Remote Code Execution

  • medium CVE-2026-7258 Fixed in 8.2.31, May 7, 2026

    Out-of-bounds read in urldecode()

  • high CVE-2025-14179 Fixed in 8.2.31, May 7, 2026

    SQL injection in pdo_firebird via NUL bytes in quoted strings

  • low CVE-2026-7568 Fixed in 8.2.31, May 7, 2026

    Signed integer overflow in metaphone()

  • low GHSA-www2-q4fc-65wf Fixed in 8.2.30, Dec 18, 2025

    Null byte termination in dns_get_record()

  • medium CVE-2025-14180 Fixed in 8.2.30, Dec 18, 2025

    NULL Pointer Dereference in PDO quoting

  • medium CVE-2025-14178 Fixed in 8.2.30, Dec 18, 2025

    Heap buffer overflow in array_merge()

  • medium CVE-2025-14177 Fixed in 8.2.30, Dec 18, 2025

    Information Leak of Memory in getimagesize

  • medium CVE-2025-1735 Fixed in 8.2.29, Jul 3, 2025

    pgsql extension does not check for errors during escaping

  • medium CVE-2025-6491 Fixed in 8.2.29, Jul 3, 2025

    NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

  • low CVE-2025-1220 Fixed in 8.2.29, Jul 3, 2025

    Null byte termination in hostnames

  • low GHSA-wg4p-4hqh-c3g9 Fixed in 8.2.28, Mar 13, 2025

    Possible out of bounds read when XML_OPTION_SKIP_TAGSTART used

  • medium CVE-2025-1219 Fixed in 8.2.28, Mar 13, 2025

    libxml streams use wrong `content-type` header when requesting a redirected resource

  • medium CVE-2025-1736 Fixed in 8.2.28, Mar 13, 2025

    Stream HTTP wrapper header check might omit basic auth header

  • medium CVE-2025-1861 Fixed in 8.2.28, Mar 13, 2025

    Stream HTTP wrapper truncate redirect location to 1024 bytes

  • medium CVE-2025-1734 Fixed in 8.2.28, Mar 13, 2025

    Streams HTTP wrapper does not fail for headers with invalid name and no colon

  • medium CVE-2025-1217 Fixed in 8.2.28, Mar 13, 2025

    Header parser of `http` stream wrapper does not handle folded headers

  • high CVE-2024-8929 Fixed in 8.2.26, Nov 21, 2024

    [Mysqlnd] Leak partial content of the heap through heap buffer over-read

  • medium CVE-2024-8932 Fixed in 8.2.26, Nov 21, 2024

    OOB access in ldap_escape

  • medium CVE-2024-11234 Fixed in 8.2.26, Nov 21, 2024

    Configuring a proxy in a stream context might allow for CRLF injection in URIs

  • medium CVE-2024-11236 Fixed in 8.2.26, Nov 21, 2024

    Integer overflow in the firebird and dblib quoters causing OOB writes

  • medium CVE-2024-11233 Fixed in 8.2.26, Nov 21, 2024

    Single byte overread with convert.quoted-printable-decode filter

  • low GHSA-4w77-75f9-2c8w Fixed in 8.2.26, Nov 21, 2024

    Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface

  • medium CVE-2024-8927 Fixed in 8.2.24, Sep 27, 2024

    cgi.force_redirect configuration is bypassable due to the environment variable collision

  • medium CVE-2024-8926 Fixed in 8.2.24, Sep 27, 2024

    PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)

  • low CVE-2024-8925 Fixed in 8.2.24, Sep 27, 2024

    Erroneous parsing of multipart form data

  • low CVE-2024-9026 Fixed in 8.2.24, Sep 27, 2024

    [PHP-FPM] Logs from childrens may be altered

  • high CVE-2024-4577 Fixed in 8.2.20, Sep 28, 2024

    PHP RCE: A Bypass of CVE-2012-1823, Argument Injection in PHP-CGI

  • high CVE-2024-5585 Fixed in 8.2.20, Jun 9, 2024

    bypass CVE-2024-1874

  • medium CVE-2024-5458 Fixed in 8.2.20, Jun 9, 2024

    Filter bypass in filter_var (FILTER_VALIDATE_URL)

  • low CVE-2024-3096 Fixed in 8.2.18, Apr 11, 2024

    password_verify can erroneously return true, opening ATO risk

  • critical CVE-2024-1874 Fixed in 8.2.18, Apr 11, 2024

    Command injection via array-ish $command parameter of proc_open even if bypass_shell option enabled on Windows

  • medium CVE-2024-2756 Fixed in 8.2.18, Apr 11, 2024

    __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix

  • low CVE-2023-3247 Fixed in 8.2.7, Jun 12, 2023

    Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

  • low CVE-2023-0567 Fixed in 8.2.3, Feb 15, 2023

    BCrypt hashes erroneously validate if the salt is cut short by `$`

  • high CVE-2023-0662 Fixed in 8.2.3, Feb 15, 2023

    DoS vulnerability when parsing multipart request body