PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
ID: b4252778-b2a0-5bc4-a3b1-a3bfc9a28613
STIX ID: report--b4252778-b2a0-5bc4-a3b1-a3bfc9a28613
Feed Name: securityonline.info
Threat Score
PHP security advisory: two vulnerabilities were fixed — a remote DoS via TLS cleanup (CVE-2026-12184, CVSS 8.2) that can crash PHP-FPM workers, and an OpenSSL AES-WRAP-PAD heap overflow (CVE-2026-14355, CVSS 5.6) that can corrupt heap metadata; patches are available for supported 8.2–8.5 branches and administrators should update immediately. No evidence of active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
