Re: [RFC] [Discussion] Hardening PHP against filter chain attacks
| From: | Sjoerd Langkemper | Date: | Fri, 22 May 2026 12:05:30 +0000 |
| Subject: | Re: [RFC] [Discussion] Hardening PHP against filter chain attacks | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-130987@lists.php.net to get a copy of this message | ||
On Thu, May 21, 2026, at 22:59, Jakub Zelenka wrote:
> Might be worth to explore if it could be through stream context option.
Yes, this is an excellent idea. I like this better than a PHP INI setting. I changed the PR and the
RFC to include a stream context option.
https://wiki.php.net/rfc/limit-maximum-number-of-filter-chains
https://github.com/php/php-src/pull/22110
Regards,
Sjoerd Langkemper