[web-php] master: Announce PHP 8.2.34

From: Date: Thu, 24 Sep 2026 13:55:11 +0000
Subject: [web-php] master: Announce PHP 8.2.34
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-34051@lists.php.net to get a copy of this message
Author: Pierrick Charron (adoy) Date: 2026-09-24T09:54:45-04:00 Commit: https://github.com/php/web-php/commit/2cff4f1fae596e18918eb0c46a0af1a669789f1c Raw diff: https://github.com/php/web-php/commit/2cff4f1fae596e18918eb0c46a0af1a669789f1c.diff Announce PHP 8.2.34 Changed paths: A public/archive/entries/2026-09-24-4.xml A public/releases/8_2_34.php M include/releases.inc M include/version.inc M public/ChangeLog-8.php M public/archive/archive.xml Diff: diff --git a/include/releases.inc b/include/releases.inc index 1240c43be7..b6df286cf8 100644 --- a/include/releases.inc +++ b/include/releases.inc @@ -2,6 +2,43 @@ $OLDRELEASES = array ( 8 => array ( + '8.2.33' => + array ( + 'announcement' => + array ( + 'English' => '/releases/8_2_33.php', + ), + 'tags' => + array ( + 0 => 'security', + ), + 'date' => '30 Jul 2026', + 'source' => + array ( + 0 => + array ( + 'filename' => 'php-8.2.33.tar.gz', + 'name' => 'PHP 8.2.33 (tar.gz)', + 'sha256' => '9a525d4db1237ede408e454b46f5a93b9e45d83d71753592e3f921903d917e07', + 'date' => '30 Jul 2026', + ), + 1 => + array ( + 'filename' => 'php-8.2.33.tar.bz2', + 'name' => 'PHP 8.2.33 (tar.bz2)', + 'sha256' => '5362f2a7a0e7168ce722fea0048b1a1d28e0f7cc265c417df670c65670695018', + 'date' => '30 Jul 2026', + ), + 2 => + array ( + 'filename' => 'php-8.2.33.tar.xz', + 'name' => 'PHP 8.2.33 (tar.xz)', + 'sha256' => 'fbdeace9b38220436a4c8fd79b900df92878151db145e641750743a283b514c1', + 'date' => '30 Jul 2026', + ), + ), + 'museum' => false, + ), '8.5.10' => array ( 'announcement' => diff --git a/include/version.inc b/include/version.inc index 5bde3043cd..e1ba94a178 100644 --- a/include/version.inc +++ b/include/version.inc @@ -58,13 +58,13 @@ $RELEASES = (function () { /* PHP 8.2 Release */ $data['8.2'] = [ - 'version' => '8.2.33', - 'date' => '30 Jul 2026', + 'version' => '8.2.34', + 'date' => '24 Sep 2026', 'tags' => ['security'], // Set to ['security'] for security releases. 'sha256' => [ - 'tar.gz' => '9a525d4db1237ede408e454b46f5a93b9e45d83d71753592e3f921903d917e07', - 'tar.bz2' => '5362f2a7a0e7168ce722fea0048b1a1d28e0f7cc265c417df670c65670695018', - 'tar.xz' => 'fbdeace9b38220436a4c8fd79b900df92878151db145e641750743a283b514c1', + 'tar.gz' => 'b42a58817acdf3e672d497a8f5314c1ee801b4ca94ebae41878bd29cf7764105', + 'tar.bz2' => '0467d63a819016811d35fd14f734764813ab149750379790634294c723cd7562', + 'tar.xz' => '5351330c54de240f54f7527c26ef292e239749e6fe11db0330acb5317e02bb39', ] ]; diff --git a/public/ChangeLog-8.php b/public/ChangeLog-8.php index 69ffa75d2a..33deec6b0b 100644 --- a/public/ChangeLog-8.php +++ b/public/ChangeLog-8.php @@ -6861,6 +6861,50 @@ <a id="PHP_8_2"></a> +<section class="version" id="8.2.34"><!-- {{{ 8.2.34 --> +<h3>Version 8.2.34</h3> +<b><?php release_date('24-Sep-2026'); ?></b> +<ul><li>Filter: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', 'ch8v-r6jh-4vvr'); ?> (FILTER_SANITIZE_ENCODED does not encode 0xFF).</li> +</ul></li> +<li>FPM: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', '62xp-839h-2637'); ?> (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768)</li> +</ul></li> +<li>MySQLnd: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', 'r6x9-5r99-36j7'); ?> (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218)</li> +</ul></li> +<li>OpenSSL: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', 'vvx9-73fr-5jjx'); ?> (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769)</li> + <li>Fixed <?php githubsecurityl('php/php-src', 'xr7j-rvgx-xq5p'); ?> (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767)</li> +</ul></li> +<li>Phar: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', 'j3wh-g957-2m85'); ?> (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103)</li> +</ul></li> +<li>SOAP: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', 'rgrp-mwpx-f6rm'); ?> (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765)</li> + <li>Fixed <?php githubsecurityl('php/php-src', 'cj93-vc83-wgqv'); ?> (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181)</li> +</ul></li> +<li>Standard: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', '88hq-2827-7pg6'); ?> (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842)</li> + <li>Fixed <?php githubsecurityl('php/php-src', 'fpwc-w8rq-cr92'); ?> (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766)</li> + <li>Fixed <?php githubsecurityl('php/php-src', '7875-c8px-7q5f'); ?> (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682)</li> +</ul></li> +<li>Windows: +<ul> + <li>Fixed <?php githubsecurityl('php/php-src', '9f67-6fw4-hpfp'); ?> (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545)</li> +</ul></li> +</ul> +<!-- }}} --></section> + + + <section class="version" id="8.2.33"><!-- {{{ 8.2.33 --> <h3>Version 8.2.33</h3> <b><?php release_date('30-Jul-2026'); ?></b> diff --git a/public/archive/archive.xml b/public/archive/archive.xml index 9026231161..d571efbb19 100644 --- a/public/archive/archive.xml +++ b/public/archive/archive.xml @@ -9,6 +9,7 @@ <uri>http://php.net/contact</uri> <email>php-webmaster@lists.php.net</email> </author> + <xi:include href="entries/2026-09-24-4.xml"/> <xi:include href="entries/2026-09-24-3.xml"/> <xi:include href="entries/2026-09-24-2.xml"/> <xi:include href="entries/2026-09-24-1.xml"/> diff --git a/public/archive/entries/2026-09-24-4.xml b/public/archive/entries/2026-09-24-4.xml new file mode 100644 index 0000000000..e38fffa71c --- /dev/null +++ b/public/archive/entries/2026-09-24-4.xml @@ -0,0 +1,21 @@ +<?xml version="1.0" encoding="utf-8"?> +<entry xmlns="http://www.w3.org/2005/Atom"> + <title>PHP 8.2.34 Released!</title> + <id>https://www.php.net/archive/2026.php#2026-09-24-4</id> + <published>2026-09-24T13:53:04+00:00</published> + <updated>2026-09-24T13:53:04+00:00</updated> + <link href="https://www.php.net/index.php#2026-09-24-4" rel="alternate" type="text/html"/> + <link href="https://www.php.net/archive/2026.php#2026-09-24-4" rel="via" type="text/html"/> + <category term="releases" label="New PHP release"/> + <category term="frontpage" label="PHP.net frontpage news"/> + <content type="xhtml"> + <div xmlns="http://www.w3.org/1999/xhtml"><p>The PHP development team announces the immediate availability of PHP 8.2.34. This is a security release.</p> + +<p>All PHP 8.2 users are encouraged to upgrade to this version.</p> + +<p>For source downloads of PHP 8.2.34 please visit our <a href="https://www.php.net/downloads.php">downloads page</a>, +Windows source and binaries can also be found <a href="https://www.php.net/downloads.php?os=windows&amp;version=8.2">there</a>. +The list of changes is recorded in the <a href="https://www.php.net/ChangeLog-8.php#8.2.34">ChangeLog</a>. +</p> </div> + </content> +</entry> diff --git a/public/releases/8_2_34.php b/public/releases/8_2_34.php new file mode 100644 index 0000000000..68c934c6bd --- /dev/null +++ b/public/releases/8_2_34.php @@ -0,0 +1,16 @@ +<?php +$_SERVER['BASE_PAGE'] = 'releases/8_2_34.php'; +require_once __DIR__ . '/../../include/prepend.inc'; +site_header('PHP 8.2.34 Release Announcement', ['cache' => true, 'cache_control' => 30 * 60]); +?> +<h1>PHP 8.2.34 Release Announcement</h1> + +<p>The PHP development team announces the immediate availability of PHP 8.2.34. This is a security release.</p> + +<p>All PHP 8.2 users are encouraged to upgrade to this version.</p> + +<p>For source downloads of PHP 8.2.34 please visit our <a href="https://www.php.net/downloads.php">downloads page</a>, +Windows source and binaries can also be found <a href="https://www.php.net/downloads.php?os=windows&amp;version=8.2">there</a>. +The list of changes is recorded in the <a href="https://www.php.net/ChangeLog-8.php#8.2.34">ChangeLog</a>. +</p> +<?php site_footer();

« previous php.webmaster (#34051) next »