PHP 8.2.34 - FPM IPv6 ACL and Stream Credential Fixes


The PHP project published tag php-8.2.34 on 24 September 2026 at 14:07 UTC as a security release for the 8.2 line. On an FPM host the change that matters first is CVE-2026-91768, a partial address comparison in listen.allowed_clients that could admit an IPv6 client the allow list did not name. The GitHub release page points at the 8.2.34 changelog for the patch list.

The full release notes and downloads are on the GitHub release page. Source archives are on the downloads page. Windows source and binaries for this branch are on the Windows 8.2 download page. The GitHub text is three short paragraphs. It names the tag and calls this a security release. The patch list is the 8.2.34 changelog, and that section is security fixes only.

Pools that set listen.allowed_clients are the access control change. GHSA-62xp-839h-2637, tracked as CVE-2026-91768, is an IPv6 ACL bypass in FastCGI. The comparison was partial, so a client address that was not the configured value could still match. A pool that treated this directive as the network ACL was not enforcing the list in the file.

The fix compares the whole address. A pool that accepted extra clients because the old comparison stopped early will start rejecting them. The directive keeps its name and its syntax. Before you restart pools, compare the strings in the pool file with the addresses you meant to allow.

Two OpenSSL fixes ship in the same binary for workers that verify certificates themselves. GHSA-vvx9-73fr-5jjx, CVE-2026-91769, stops hostname verification from falling back to the common name after a subject alternative name mismatch. A SAN mismatch fails the check. A certificate that failed the SAN and then passed on the common name stops connecting. GHSA-xr7j-rvgx-xq5p, CVE-2026-91767, is a heap buffer overflow in php_openssl_matches_wildcard_name() on a crafted wildcard common name. HTTPS fetches through PHP streams hit that function when the peer certificate uses a wildcard. A process that never loads OpenSSL, because a proxy terminates TLS, skips this function and can still hit the FPM bug.

Batch fetchers and older CMS code still read URLs with the HTTP stream wrapper. file_get_contents() and fopen() on an http or https URL use it. GHSA-fpwc-w8rq-cr92, CVE-2026-91766, is a cross origin credential leak when the wrapper follows a redirect. Credentials on the first URL could be sent to another origin. After the fix, a redirect to another origin does not take them. A job that reached a downstream host only because of that leak can fail authentication until you attach credentials to the origin that answers.

GHSA-7875-c8px-7q5f, CVE-2026-93682, is an out of bounds read in the same wrapper when the redirect Location header is empty. The changelog adds no ini setting. The corrected wrapper is the new binary.

GHSA-88hq-2827-7pg6, CVE-2026-92842, is an out of bounds read in convert.* stream filters when line-break-chars contains a NUL. Callers that put a NUL in line-break-chars while normalizing CSV, logs, or fetched text are the ones in range. A chain that never sets that argument skips this bug and still needs the redirect fixes.

GHSA-ch8v-r6jh-4vvr has no CVE id in the changelog. FILTER_SANITIZE_ENCODED left the byte 0xFF unencoded. This release encodes it, so stored filter output changes for inputs that contain that byte. If you persist the result, compare one such payload on the old binary and on php-8.2.34 before you call the rollout done.

GHSA-r6x9-5r99-36j7, CVE-2025-1218, fixes packet overreads in the mysqlnd wire protocol. The client parses server packets in the PHP process, and a malformed packet could read past the bytes that arrived. mysqli and PDO MySQL hit the bug when mysqlnd is the driver. SQL syntax, prepared statements, and result shapes stay the same. The CVE id is from 2025. On the 8.2 branch, this tag is the changelog entry for the fix.

SOAP servers get two parser fixes and no new configuration. GHSA-rgrp-mwpx-f6rm, CVE-2026-91765, fixes unbounded recursion in server side cleanup_xml_node(). A document that drives cleanup deep enough can exhaust the stack. GHSA-cj93-vc83-wgqv, CVE-2025-14181, is an integer overflow that becomes a buffer overflow while parsing SOAP over HTTP. Neither fix changes the SOAP extension API.

GHSA-j3wh-g957-2m85, CVE-2026-6103, is an integer overflow in phar_tar_number() that allows TAR archive entry injection. Opening a phar built from tar input could inject an archive entry. There is no new method and no new flag. If that input comes from outside the process, older 8.2 builds keep the vulnerable parser.

GHSA-9f67-6fw4-hpfp, CVE-2026-17545, rejects reserved Windows device names before file and stream I/O. Those names were reaching the I/O layer. Linux workers do not take this path. Windows task runners do, through the binaries on the Windows download page linked above. An agent left on the previous 8.2 tag stays exposed after the Linux fleet moves to php-8.2.34.

The announcement asks every PHP 8.2 user to upgrade. The changelog lists no renamed setting and no migration step. After the package bump, check FPM allow lists, HTTP redirects that carry credentials, and any store of FILTER_SANITIZE_ENCODED output.