PHP 8.3

Status Security onlySupport 2023-11 – 2027-12Latest 8.3.31Vulnerabilities 29← All PHP versions
Critical 9.8
2024-11-22< 8.3.14

OOB access in ldap_escape

Critical 9.8
2025-01-01< 8.3.19

Stream HTTP wrapper truncates redirect location to 1024 bytes

Critical 9.8
2024-11-24< 8.3.14

Integer overflow in the firebird and dblib quoters causing OOB writes

KEV
2024-06-09< 8.3.8

Argument Injection in PHP-CGI

Critical 9.4
2024-04-29< 8.3.8

Command injection via array-ish $command parameter of proc_open()

High 8.1
2025-04-04< 8.3.19

Reference counting in php_request_shutdown causes Use-After-Free

High 8.1
2024-10-08< 8.3.12

PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)

High 7.7
2024-06-09< 8.3.8

Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)

High 7.5
2025-12-27< 8.3.29

NULL Pointer Dereference in PDO quoting

High 7.5
2025-12-27< 8.3.29

Information Leak of Memory in getimagesize

High 7.5
2024-04-29< 8.3.6

PHP mb_encode_mimeheader runs endlessly for some inputs

High 7.5
2024-10-08< 8.3.12

cgi.force_redirect configuration is bypassable due to the environment variable collision

High 7.3
2025-01-01< 8.3.19

Stream HTTP wrapper header check might omit basic auth header

Medium 6.5
2025-12-27< 8.3.29

Heap buffer overflow in array_merge()

Medium 6.5
2024-04-29< 8.3.6

PHP function password_verify can erroneously return true when argument contains NUL

Medium 5.9
2025-07-05< 8.3.23

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

Medium 5.9
2025-07-05< 8.3.23

pgsql extension does not check for errors during escaping

Medium 5.9
2024-06-09< 8.3.8

PHP is vulnerable to the Marvin Attack

Medium 5.8
2024-11-22< 8.3.14

Leak partial content of the heap through heap buffer over-read in mysqlnd

Medium 5.3
2025-01-01< 8.3.19

Streams HTTP wrapper does not fail for headers with invalid name and no colon

Medium 5.3
2025-01-01< 8.3.19

libxml streams use wrong content-type header when requesting a redirected resource

Medium 5.3
2024-06-09< 8.3.8

Filter bypass in filter_var (FILTER_VALIDATE_URL)

Medium 4.8
2024-11-24< 8.3.14

Configuring a proxy in a stream context might allow for CRLF injection in URIs

Medium 4.8
2024-11-24< 8.3.14

Single byte overread with convert.quoted-printable-decode filter

Low 3.7
2025-07-13< 8.3.23

Null byte termination in hostnames

Low 3.3
2024-10-08< 8.3.12

PHP-FPM logs from children may be altered

Low 3.1
2025-01-01< 8.3.19

Header parser of http stream wrapper does not handle folded headers

Low 3.1
2024-10-08< 8.3.12

Erroneous parsing of multipart form data

N/A
2024-04-29< 8.3.6