RHSA-2026:22305HighCVSS 7.5
Red Hat Security Advisory: php:8.2 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-6735 — PHP: PHP-FPM: PHP-FPM: Cross-Site Scripting vulnerability via improper URL sanitation CVE-2026-7258 — PHP: PHP: Denial of Service via improper handling of signed characters in ctype functions CVE-2026-7262 — php: NULL pointer dereference in SOAP apache:Map decoder with missing CVE-2026-7568 — php: signed integer overflow in metaphone()
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:22305
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2468561
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2468562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2468565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2468566
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22305.json