Author: Jakub Zelenka (bukka)
Date: 2026-09-24T12:04:37+02:00
Commit:
https://github.com/php/web-php/commit/967eedf83f2ff3f775a1435cbab8cdac334a7871
Raw diff:
https://github.com/php/web-php/commit/967eedf83f2ff3f775a1435cbab8cdac334a7871.diff
Announce PHP 8.3.35
Changed paths:
A public/archive/entries/2026-09-24-2.xml
A public/releases/8_3_35.php
M public/ChangeLog-8.php
M public/archive/archive.xml
Diff:
diff --git a/public/ChangeLog-8.php b/public/ChangeLog-8.php
index c5f1dac9af..7c0b953dd4 100644
--- a/public/ChangeLog-8.php
+++ b/public/ChangeLog-8.php
@@ -3937,6 +3937,50 @@
<a id="PHP_8_3"></a>
+<section class="version" id="8.3.35"><!-- {{{ 8.3.35 -->
+<h3>Version 8.3.35</h3>
+<b><?php release_date('24-Sep-2026'); ?></b>
+<ul><li>Filter:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'ch8v-r6jh-4vvr'); ?>
(FILTER_SANITIZE_ENCODED does not encode 0xFF).</li>
+</ul></li>
+<li>FPM:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', '62xp-839h-2637'); ?> (IPv6
ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison). (CVE-2026-91768)</li>
+</ul></li>
+<li>MySQLnd:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'r6x9-5r99-36j7'); ?>
(Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218)</li>
+</ul></li>
+<li>OpenSSL:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'vvx9-73fr-5jjx'); ?> (TLS
hostname verification falls back to CN after SAN mismatch).
(CVE-2026-91769)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'xr7j-rvgx-xq5p'); ?> (Heap
buffer overflow in php_openssl_matches_wildcard_name() on crafted server
certificate wildcard CN). (CVE-2026-91767)</li>
+</ul></li>
+<li>Phar:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'j3wh-g957-2m85'); ?>
(Integer overflow in phar_tar_number() allowing TAR archive entry injection).
(CVE-2026-6103)</li>
+</ul></li>
+<li>SOAP:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'rgrp-mwpx-f6rm'); ?>
(Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'cj93-vc83-wgqv'); ?>
(Integer overflow to buffer overflow in SOAP HTTP parsing).
(CVE-2025-14181)</li>
+</ul></li>
+<li>Standard:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', '88hq-2827-7pg6'); ?>
(Out-of-bounds read in convert.* stream filters when line-break-chars contains
NUL). (CVE-2026-92842)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'fpwc-w8rq-cr92'); ?>
(Cross-origin credential leak in HTTP stream wrapper redirects).
(CVE-2026-91766)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', '7875-c8px-7q5f'); ?>
(Out-of-bounds read in the HTTP stream wrapper when following a redirect with
an empty Location header). (CVE-2026-93682)</li>
+</ul></li>
+<li>Windows:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', '9f67-6fw4-hpfp'); ?>
(Reserved device names are not rejected before file and stream I/O).
(CVE-2026-17545)</li>
+</ul></li>
+</ul>
+<!-- }}} --></section>
+
+
+
<section class="version" id="8.3.33"><!-- {{{ 8.3.33 -->
<h3>Version 8.3.33</h3>
<b><?php release_date('30-Jul-2026'); ?></b>
diff --git a/public/archive/archive.xml b/public/archive/archive.xml
index fd75ead041..e6ff9e64bb 100644
--- a/public/archive/archive.xml
+++ b/public/archive/archive.xml
@@ -9,6 +9,7 @@
<uri>http://php.net/contact</uri>
<email>[email protected]</email>
</author>
+ <xi:include href="entries/2026-09-24-2.xml"/>
<xi:include href="entries/2026-09-24-1.xml"/>
<xi:include href="entries/2026-09-11-1.xml"/>
<xi:include href="entries/2026-09-10-1.xml"/>
diff --git a/public/archive/entries/2026-09-24-2.xml
b/public/archive/entries/2026-09-24-2.xml
new file mode 100644
index 0000000000..4bcfa9272e
--- /dev/null
+++ b/public/archive/entries/2026-09-24-2.xml
@@ -0,0 +1,21 @@
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom">
+ <title>PHP 8.3.35 Released!</title>
+ <id>https://www.php.net/archive/2026.php#2026-09-24-2</id>
+ <published>2026-09-24T09:51:44+00:00</published>
+ <updated>2026-09-24T09:51:44+00:00</updated>
+ <link href="https://www.php.net/index.php#2026-09-24-2" rel="alternate"
type="text/html"/>
+ <link href="https://www.php.net/archive/2026.php#2026-09-24-2" rel="via"
type="text/html"/>
+ <category term="releases" label="New PHP release"/>
+ <category term="frontpage" label="PHP.net frontpage news"/>
+ <content type="xhtml">
+ <div xmlns="http://www.w3.org/1999/xhtml"><p>The PHP development team
announces the immediate availability of PHP 8.3.35. This is a security
release.</p>
+
+<p>All PHP 8.3 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.3.35 please visit our <a
href="https://www.php.net/downloads.php">downloads page</a>,
+Windows source and binaries can also be found <a
href="https://www.php.net/downloads.php?os=windows&version=8.3">there</a>.
+The list of changes is recorded in the <a
href="https://www.php.net/ChangeLog-8.php#8.3.35">ChangeLog</a>.
+</p> </div>
+ </content>
+</entry>
diff --git a/public/releases/8_3_35.php b/public/releases/8_3_35.php
new file mode 100644
index 0000000000..2adc74198a
--- /dev/null
+++ b/public/releases/8_3_35.php
@@ -0,0 +1,16 @@
+<?php
+$_SERVER['BASE_PAGE'] = 'releases/8_3_35.php';
+require_once __DIR__ . '/../../include/prepend.inc';
+site_header('PHP 8.3.35 Release Announcement', ['cache' => true,
'cache_control' => 30 * 60]);
+?>
+<h1>PHP 8.3.35 Release Announcement</h1>
+
+<p>The PHP development team announces the immediate availability of PHP
8.3.35. This is a security release.</p>
+
+<p>All PHP 8.3 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.3.35 please visit our <a
href="https://www.php.net/downloads.php">downloads page</a>,
+Windows source and binaries can also be found <a
href="https://www.php.net/downloads.php?os=windows&version=8.3">there</a>.
+The list of changes is recorded in the <a
href="https://www.php.net/ChangeLog-8.php#8.3.35">ChangeLog</a>.
+</p>
+<?php site_footer();