Skip to main content

PHP 8.5.11

Release Date: September 24, 2026

Overview: PHP 8.5.11, released September 24, 2026, is a security release. All PHP 8.5 users are encouraged to upgrade. The update resolves a series of CVEs affecting the stream wrapper, OpenSSL, FPM, SOAP, Phar and Windows, alongside a large body of component bug fixes.

Security Fixes

  • CVE-2026-91769: OpenSSL TLS hostname verification falls back to the common name after a SAN mismatch.
  • CVE-2026-91767: Heap buffer overflow in php_openssl_matches_wildcard_name() on a crafted server certificate wildcard CN.
  • CVE-2026-91768: FPM IPv6 ACL bypass in FastCGI listen.allowed_clients due to a partial address comparison.
  • CVE-2025-1218: Various packet overreads in the mysqlnd wire protocol.
  • CVE-2026-6103: Integer overflow in phar_tar_number() allowing TAR archive entry injection.
  • CVE-2026-91765: Unbounded recursion in the SOAP server-side cleanup_xml_node().
  • CVE-2025-14181: Integer overflow to buffer overflow in SOAP HTTP parsing.
  • CVE-2026-93682: Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header.
  • CVE-2026-91766: Cross-origin credential leak in HTTP stream wrapper redirects.
  • CVE-2026-92842: Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL.
  • CVE-2026-17545: Reserve device names not rejected before Windows file and stream I/O.

Bug Fixes

Core fixes out-of-bounds reads during automatic UTF-16/32 encoding detection, and resolves nested "yield from" issues where items were skipped or yielded twice (GH-15375, GH-23301). DOM work fixes a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(), stale getElementsByClassName() and node list caches, and crashes in DOMXPath callbacks. Intl repairs grapheme_strpos() empty-needle offsets and a double-free in IntlGregorianCalendar construction. Opcache addresses a ZTS protect_memory race and a tracing JIT crash, and the FPM build fixes a UID/GID overflow (GH-19320).

Additional fixes span BCMath, GD error messages, MBString backreference replacement, ODBC field functions returning uninitialized memory, PDO persistent-connection leaks, Phar use-after-free and duplicate manifest memory leaks, SOAP WSDL cache corruption and a stack overflow on self-referential schema groups, SimpleXML namespace attribute handling, ZipArchive stream and garbage-collection bugs, plus Standard stream filter and array_keys() index corrections.

Other Versions

By continuing to use the site, you agree to the use of cookies.