CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

PHP Group security advisory (AV26-764)

unknown
Serial number: AV26-764 Date: July 30, 2026 As of July 30, 2026, PHP Group is affected by vulnerabilities in the following product: PHP Prior to 8.2.33 Prior to 8.3.33 Prior to 8.4.24 Prior to 8.5.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SQL injection in ext-pgsql via E'...' backslash breakout Out-of-bounds write in bccomp() via crafted operand and scale

CSIRTS triage

vendor: PHP Groupproduct: PHPSQL injectionOtheraffected: Prior to 8.2.33, 8.3.33, 8.4.24, 8.5.9
What
PHP is affected by SQL injection and out-of-bounds write vulnerabilities.
Who is affected
Users and administrators of PHP versions prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9.
Urgency
Remediation is important due to the potential for exploitation, though severity is unknown.
Action
Review the provided web links and apply necessary updates as they become available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch PHP

Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-30
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/php-group-security-advisory-av26-764

More from Canadian Centre for Cyber Security