PHP 8.4

Status MaintainedSupport 2024-11 – 2028-12Latest 8.4.21Vulnerabilities 12← All PHP versions
Critical 9.8
2025-01-01< 8.4.5

Stream HTTP wrapper truncates redirect location to 1024 bytes

High 8.1
2025-04-04< 8.4.5

Reference counting in php_request_shutdown causes Use-After-Free

High 7.5
2025-12-27< 8.4.16

NULL Pointer Dereference in PDO quoting

High 7.5
2025-12-27< 8.4.16

Information Leak of Memory in getimagesize

High 7.3
2025-01-01< 8.4.5

Stream HTTP wrapper header check might omit basic auth header

Medium 6.5
2025-12-27< 8.4.16

Heap buffer overflow in array_merge()

Medium 5.9
2025-07-05< 8.4.10

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

Medium 5.9
2025-07-05< 8.4.10

pgsql extension does not check for errors during escaping

Medium 5.3
2025-01-01< 8.4.5

Streams HTTP wrapper does not fail for headers with invalid name and no colon

Medium 5.3
2025-01-01< 8.4.5

libxml streams use wrong content-type header when requesting a redirected resource

Low 3.7
2025-07-13< 8.4.10

Null byte termination in hostnames

Low 3.1
2025-01-01< 8.4.5

Header parser of http stream wrapper does not handle folded headers