logo

PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug

ID: b4252778-b2a0-5bc4-a3b1-a3bfc9a28613

STIX ID: report--b4252778-b2a0-5bc4-a3b1-a3bfc9a28613

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-07-06

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

PHP security advisory: two vulnerabilities were fixed — a remote DoS via TLS cleanup (CVE-2026-12184, CVSS 8.2) that can crash PHP-FPM workers, and an OpenSSL AES-WRAP-PAD heap overflow (CVE-2026-14355, CVSS 5.6) that can corrupt heap metadata; patches are available for supported 8.2–8.5 branches and administrators should update immediately. No evidence of active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.