CVE-2026-92842: PHP PHP vulnerability
Published Sep 24, 2026
·Updated
Fixed (Out-of-bounds read in convert. stream filters when line-break-chars contains NUL). (CVE-2026-92842)
Affected Software
1 affected componentFixes available
PHP PHP<8.4.26
8.4.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.26
Event History
Sep 24, 2026
CVE Published
via PHP·12:00 AM
Data Sourced
via PHP·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which PHP release is identified as containing the fix?
The provided reference points to the PHP 8.3.35 changelog for this fix.