PHP Group security advisory (AV26-764)
Serial number: AV26-764 Date: July 30, 2026 As of July 30, 2026, PHP Group is affected by vulnerabilities in the following product: PHP Prior to 8.2.33 Prior to 8.3.33 Prior to 8.4.24 Prior to 8.5.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SQL injection in ext-pgsql via E'...' backslash breakout Out-of-bounds write in bccomp() via crafted operand and scale
CSIRTS triage
- What
- PHP is affected by SQL injection and out-of-bounds write vulnerabilities.
- Who is affected
- Users and administrators of PHP versions prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9.
- Urgency
- Remediation is important due to the potential for exploitation, though severity is unknown.
- Action
- Review the provided web links and apply necessary updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PHP
Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/php-group-security-advisory-av26-764
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownVMware security advisory (AV26-763)2026-07-30