PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.
Security Fix(es):
php: ext/openssl: memory corruption in openssl_encrypt with AES-WRAP-PAD (CVE-2026-14355)
php: ext-pgsql: PHP: SQL injection via improper backslash escaping (CVE-2026-17543)
php: PHP: Denial of Service via circular symbolic links in phar archives (CVE-2026-7260)
Bug Fix(es) and Enhancement(s):
Backport fix for CVE-2026-14355 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-192624)
Backport fix for CVE-2026-17543 and CVE-2026-7260 to PHP 8.0 in 9.8.z (JIRA:Rocky Linux-223940)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"source_advisory": "RHSA-2026:61259",
"license": "CC-BY-4.0",
"license_url": "https://creativecommons.org/licenses/by/4.0/"
}