CVE-2026-12184: PHP PHP vulnerability
Fixed bug (Segfault in filegetcontents w/ a https URL and a proxy set). (CVE-2026-12184)
Other sources
PHP: Failure to setup TLS with a remote server can result in a remote DoS
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.21 - Upgrade
Upgrade
debian/php7.4to a version that resolves this vulnerability.Fixed in 7.4.33-1+deb11u5Fixed in 7.4.33-1+deb11u11 - Upgrade
Upgrade
debian/php8.2to a version that resolves this vulnerability.Fixed in 8.2.32-1~deb12u1 - Upgrade
Upgrade
debian/php8.4to a version that resolves this vulnerability.Fixed in 8.4.23-1~deb13u1Fixed in 8.4.23-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12184?
CVE-2026-12184 has a risk rating of 17, indicating a moderate severity level.
How does CVE-2026-12184 affect PHP?
CVE-2026-12184 causes a segmentation fault in the file_get_contents function when using an HTTPS URL with a proxy set.
How do I fix CVE-2026-12184?
To mitigate CVE-2026-12184, update your PHP installation to the latest version where the bug has been fixed.
When was CVE-2026-12184 published?
CVE-2026-12184 was published on July 2, 2026.
What versions of PHP are affected by CVE-2026-12184?
CVE-2026-12184 affects specific versions of PHP that are prior to the fix implemented in PHP 8.3.32.