VYPR

php8.2

by Debian

CVEs (3)

  • CVE-2026-17544Jul 31, 2026
    risk 0.00cvss epss

    Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

  • CVE-2026-17543Jul 31, 2026
    risk 0.00cvss epss

    Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

  • CVE-2026-7260Jul 31, 2026
    risk 0.00cvss epss

    Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.