The PHP project published php-8.4.26 on 24 September 2026 at 18:42 UTC. The GitHub release calls the tag a security release and encourages every 8.4 user to upgrade. For database clients the leading fix is CVE-2025-1218, packet overreads in the mysqlnd wire protocol.
The full release notes and downloads are on the GitHub release page. The announcement is the upgrade notice. The itemized list is the PHP 8.4.26 changelog.
MySQL clients, PDO, and generators ¶
CVE-2025-1218 covers packet overreads in the mysqlnd wire protocol. mysqli and PDO MySQL both read result rows through that parser. A truncated or malformed packet can be read past the end of its buffer.
Client library fixes sit next to that parser fix. A persistent PDO connection that fails its liveness check leaks when no other live PDO handle remains. On pdo_pgsql, PDO::CURSOR_SCROLL closed a cursor that does not exist. GH-20214 changes PDO::FETCH_DEFAULT after PDOStatement::setFetchMode on the PDO sqlite driver. GH-23444 reports that ODBC_ATTR_ASSUME_UTF8 corrupts Unicode data outside Windows. odbc_field_len(), odbc_field_scale(), and odbc_field_type() could return uninitialized memory when SQLColAttribute failed.
Nested yield from can drop or repeat rows. GH-15375 skips items after valid() or next() on the inner generator. GH-23301 yields a value twice when the middle generator delegates again. An export that chains generators can change its row count on this tag. Code that depended on the skipped or repeated value will see different output.
HTTP streams and TLS hostname checks ¶
Three stream bugs carry CVE ids. CVE-2026-91766 is a cross origin credential leak on HTTP stream wrapper redirects. Credentials on the request could follow a redirect onto another origin. CVE-2026-93682 is an out of bounds read when the redirect Location header is empty. CVE-2026-92842 is an out of bounds read in convert.* filters when line-break-chars contains a NUL. A filter callback that unsets StreamBucket::$data and then attaches the bucket again could segfault. php_stream_filter_flush() compacted its read buffer incorrectly.
CVE-2026-91769 stops TLS hostname verification from falling back to the certificate CN after a SAN mismatch. file_get_contents and other https:// stream wrappers that passed only because of that fallback will fail the check. A host that still presents a mismatched SAN and a CN equal to the requested name breaks fetch jobs until the certificate is replaced. CVE-2026-91767 is a heap buffer overflow in php_openssl_matches_wildcard_name() on a crafted wildcard CN. hash_pbkdf2() overflowed a buffer when the requested output length was large, so key derivation with a long length should leave older 8.4 builds.
FPM, opcache, archives, and SOAP ¶
CVE-2026-91768 is an IPv6 ACL bypass in FastCGI. listen.allowed_clients compared only part of the address, so an allowed entry could match a different host. GH-19320 fixes overflow of FPM UID and GID values. An overflowing id is not the account configured for the pool.
Opcache work here removes crashes and adds no ini key. opcache.protect_memory raced under ZTS. A huge page remap of shared memory could discard mappings outside the reserved address range. GH-23288 crashed on restart when opcache.interned_strings_buffer was overridden in one FPM pool. The tracing JIT could crash while compiling a side trace for a method whose class could not be stored in the inheritance cache.
Phar and Zip cover deploy artifacts and ingest. CVE-2026-6103 is an integer overflow in phar_tar_number() that allows TAR archive entry injection. GH-23418 is a use after free when looking up mounted Phar directories. ZipArchive::extractTo() and ZipArchive::getFrom*() could report success on corrupted entries. A true return from an extract on older 8.4 is not proof the payload is intact. fstat() on a zip:// stream could report success when the archive could not be opened.
SOAP servers get two memory safety fixes. CVE-2026-91765 is unbounded recursion in server side cleanup_xml_node(). CVE-2025-14181 turns an integer overflow into a buffer overflow while parsing SOAP HTTP. A soap:header that defines headerfaults could corrupt the WSDL cache. A self referential schema group or attributeGroup in a WSDL could overflow the stack. On Windows, CVE-2026-17545 rejects reserved device names before file and stream I/O. Intl offset fixes, DOM use after free fixes, and GH-23457 (imagebmp() file writes) are also on the changelog. They do not change the MySQL, stream, or FPM behavior above.
Where to get it ¶
- Release page: PHP 8.4.26 on GitHub
- Source downloads: php.net downloads
- Windows builds: PHP 8.4 Windows downloads
- Changelog: PHP 8 changelog for 8.4.26
- Repository:
php/php-src - Tag:
php-8.4.26