From 398b316ce6f57e0cda0412dcc57bccd0276e0b67 Mon Sep 17 00:00:00 2001 From: Patrick Dawkins Date: Fri, 25 Sep 2026 16:51:00 +0100 Subject: [PATCH] chore: update PHP to 8.4.26 Security fixes since 8.4.23 in code the CLI uses include: - OpenSSL: TLS hostname verification fell back to the CN after a SAN mismatch (CVE-2026-91769), and a heap buffer overflow on a crafted wildcard CN (CVE-2026-91767). - HTTP stream wrapper: a cross-origin credential leak on redirects (CVE-2026-91766), and an out-of-bounds read on an empty Location header (CVE-2026-93682). - Phar: TAR entry injection via an integer overflow (CVE-2026-6103), and a crash via recursive symlinks (CVE-2026-7260, 8.4.24). - Windows: reserved device names were not rejected before file I/O (CVE-2026-17545). The binaries come from upsun/cli-php-builds, whose macOS x86_64 build now uses the standalone static-php-cli binary (upsun/cli-php-builds#2). Co-Authored-By: Claude Opus 5.5 --- Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile b/Makefile index 82af0357..958a7507 100644 --- a/Makefile +++ b/Makefile @@ -1,4 +1,4 @@ -PHP_VERSION = 8.4.23 +PHP_VERSION = 8.4.26 GOOS := $(shell uname -s | tr '[:upper:]' '[:lower:]') GOARCH := $(shell uname -m)