Author: Volker Dusch (edorian)
Date: 2026-09-24T13:43:21+02:00
Commit:
https://github.com/php/web-php/commit/a2e765bf9d69016f2473eedb975d2acbac4bbbac
Raw diff:
https://github.com/php/web-php/commit/a2e765bf9d69016f2473eedb975d2acbac4bbbac.diff
Announce PHP 8.5.11
Changed paths:
A public/archive/entries/2026-09-24-3.xml
A public/releases/8_5_11.php
M include/release-qa.php
M include/releases.inc
M include/version.inc
M public/ChangeLog-8.php
M public/archive/archive.xml
Diff:
diff --git a/include/release-qa.php b/include/release-qa.php
index 4a6e111efd..43c4ea1db0 100644
--- a/include/release-qa.php
+++ b/include/release-qa.php
@@ -88,10 +88,10 @@
'active' => true,
'release' => [
'type' => 'RC',
- 'number' => 1,
- 'sha256_bz2' =>
'24574eb0c8c1bceac833a5b984fcfb0cde50a019f6a757c35f28da3dc97300b9',
- 'sha256_gz' =>
'dd0a2dc233ee6dd6d8ef389b671fefc5cd0f49b859d16e53d875582c5e248bbb',
- 'sha256_xz' =>
'84e5d0abc91f6b1f69de6c5ec5d3720124582417c7ce6c5df742dcbada179a82',
+ 'number' => 0,
+ 'sha256_bz2' => '',
+ 'sha256_gz' => '',
+ 'sha256_xz' => '',
'date' => '10 September 2026',
'baseurl' => 'https://downloads.php.net/~edorian/',
],
diff --git a/include/releases.inc b/include/releases.inc
index dff5fb77f1..1240c43be7 100644
--- a/include/releases.inc
+++ b/include/releases.inc
@@ -2,6 +2,43 @@
$OLDRELEASES = array (
8 =>
array (
+ '8.5.10' =>
+ array (
+ 'announcement' =>
+ array (
+ 'English' => '/releases/8_5_10.php',
+ ),
+ 'tags' =>
+ array (
+ 0 => '',
+ ),
+ 'date' => '27 Aug 2026',
+ 'source' =>
+ array (
+ 0 =>
+ array (
+ 'filename' => 'php-8.5.10.tar.gz',
+ 'name' => 'PHP 8.5.10 (tar.gz)',
+ 'sha256' =>
'f5c0ac99b85b3d677de475c2e4f509f9b4f54663f3ee5a84d6d9481a521d4100',
+ 'date' => '27 Aug 2026',
+ ),
+ 1 =>
+ array (
+ 'filename' => 'php-8.5.10.tar.bz2',
+ 'name' => 'PHP 8.5.10 (tar.bz2)',
+ 'sha256' =>
'd79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e',
+ 'date' => '27 Aug 2026',
+ ),
+ 2 =>
+ array (
+ 'filename' => 'php-8.5.10.tar.xz',
+ 'name' => 'PHP 8.5.10 (tar.xz)',
+ 'sha256' =>
'6a8bebaa4d5a979a38db29a9373e9851f60c6b11f72172c585947e78f3081957',
+ 'date' => '27 Aug 2026',
+ ),
+ ),
+ 'museum' => false,
+ ),
'8.5.9' =>
array (
'announcement' =>
diff --git a/include/version.inc b/include/version.inc
index d5b521d83a..5bde3043cd 100644
--- a/include/version.inc
+++ b/include/version.inc
@@ -20,15 +20,15 @@ $RELEASES = (function () {
/* PHP 8.5 Release */
$data['8.5'] = [
- 'version' => '8.5.10',
- 'date' => '27 Aug 2026',
- 'tags' => [''], // Set to ['security'] for security releases.
+ 'version' => '8.5.11',
+ 'date' => '24 Sep 2026',
+ 'tags' => ['security'], // Set to ['security'] for security releases.
'sha256' => [
// WARNING: Order of SHA256 entries here is DIFFERENT from the
// order in the manifest
- 'tar.gz' =>
'f5c0ac99b85b3d677de475c2e4f509f9b4f54663f3ee5a84d6d9481a521d4100',
- 'tar.bz2' =>
'd79bd4f3a9248e5cb5833766ba0d51cd35dd01b8727f23f30bcdba6fabc51d3e',
- 'tar.xz' =>
'6a8bebaa4d5a979a38db29a9373e9851f60c6b11f72172c585947e78f3081957',
+ 'tar.gz' =>
'338630ba9450f0b938bef8d740162c61c33bf64a1b421c6333c01df8a9fdb0ab',
+ 'tar.bz2' =>
'dc940716a8c73e531c0078eecb955d595d321ec2cc9d47149cf0089ea6e18f64',
+ 'tar.xz' =>
'd9be75c08e8c316f4c8f4194d8fbe1750a15f6a6d9d4e3fe72082abeeb800360',
]
];
diff --git a/public/ChangeLog-8.php b/public/ChangeLog-8.php
index 7c0b953dd4..69ffa75d2a 100644
--- a/public/ChangeLog-8.php
+++ b/public/ChangeLog-8.php
@@ -9,6 +9,137 @@
<a id="PHP_8_5"></a>
+<section class="version" id="8.5.11"><!-- {{{ 8.5.11 -->
+<h3>Version 8.5.11</h3>
+<b><?php release_date('24-Sep-2026'); ?></b>
+<ul><li>BCMath:
+<ul>
+ <li>Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds
n_scale.</li>
+</ul></li>
+<li>Core:
+<ul>
+ <li>Fixed out-of-bounds reads during automatic UTF-16/32 encoding
detection.</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 15375); ?> (Nested "yield
from" skips items after a valid() or next() call on the inner generator).</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23232); ?> (lone namespace
separator asks the autoloader for an empty class name).</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23301); ?> (Nested "yield
from" yields a value twice when the middle generator delegates again).</li>
+</ul></li>
+<li>DOM:
+<ul>
+ <li>Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the
null namespace in spec-following mode.</li>
+ <li>Fixed stale getElementsByClassName() and other node list caches after
className/classList writes and attribute removals.</li>
+ <li>Fixed a use-after-free when cloning a DOMNameSpaceNode after
DOMDocument::xinclude().</li>
+ <li>Fixed a crash in DOMXPath when a php:function callback receives a
nodeset and a later callback returns a node from another document.</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23331); ?> (UAF when
node_list_unlink() skips attribute children that still have a live
wrapper).</li>
+ <li>Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the
value of an attribute whose child still has a live wrapper.</li>
+</ul></li>
+<li>GD:
+<ul>
+ <li>Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the
wrong argument in error messages.</li>
+</ul></li>
+<li>FPM:
+<ul>
+ <li>Fixed bug <?php githubissuel('php/php-src', 19320); ?> (FPM UID and GID
overflow).</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', '62xp-839h-2637'); ?> (IPv6
ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison). (CVE-2026-91768)</li>
+</ul></li>
+<li>Intl:
+<ul>
+ <li>Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle
returning UTF-16 offsets instead of grapheme offsets.</li>
+ <li>Fixed a memory leak when dumping IntlCalendar instances.</li>
+ <li>Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator()
results.</li>
+ <li>Fixed a double-free when IntlGregorianCalendar construction fails after
the ICU constructor adopts the TimeZone.</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23094); ?> (NumberFormatter
parsing offsets use UTF-16 positions for UTF-8 strings).</li>
+ <li>Fixed Locale::parseLocale() reading past a trailing '-' or '_'.</li>
+ <li>Fixed grapheme_str_split() treating UBRK_DONE as a byte index.</li>
+ <li>Fixed a leak in Locale::getKeywords() when a keyword value cannot be
read.</li>
+ <li>Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed
from compiled rules.</li>
+</ul></li>
+<li>MBString:
+<ul>
+ <li>Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the
replacement when a \k<name> backref has no closing delimiter.</li>
+</ul></li>
+<li>MySQLnd:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'r6x9-5r99-36j7'); ?>
(Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218)</li>
+</ul></li>
+<li>ODBC:
+<ul>
+ <li>Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type()
returning uninitialized memory when SQLColAttribute fails.</li>
+</ul></li>
+<li>Opcache:
+<ul>
+ <li>Fixed opcache.protect_memory race under ZTS.</li>
+ <li>Fixed a tracing JIT crash when compiling a side trace for a method of a
class that could not be stored in the inheritance cache.</li>
+ <li>Fixed a crash when the huge page SHM remap discarded mappings outside
the reserved address range.</li>
+</ul></li>
+<li>OpenSSL:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'vvx9-73fr-5jjx'); ?> (TLS
hostname verification falls back to CN after SAN mismatch).
(CVE-2026-91769)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'xr7j-rvgx-xq5p'); ?> (Heap
buffer overflow in php_openssl_matches_wildcard_name() on crafted server
certificate wildcard CN). (CVE-2026-91767)</li>
+</ul></li>
+<li>PDO:
+<ul>
+ <li>Fixed a leak when a persistent connection failed a liveness check with
no other live PDO handle.</li>
+</ul></li>
+<li>PDO_PGSQL:
+<ul>
+ <li>Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching
(PDO::ATTR_PREFETCH => 0).</li>
+</ul></li>
+<li>PDO Sqlite:
+<ul>
+ <li>Fixed bug <?php githubissuel('php/php-src', 20214); ?>
(PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode).</li>
+</ul></li>
+<li>Phar:
+<ul>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23418); ?> (Use-after-free
when looking up mounted directories).</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23477); ?> (Memory leak on
duplicate native Phar manifest entries).</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'j3wh-g957-2m85'); ?>
(Integer overflow in phar_tar_number() allowing TAR archive entry injection).
(CVE-2026-6103)</li>
+</ul></li>
+<li>Readline:
+<ul>
+ <li>Fixed the interactive shell not waiting for the pager process to
exit.</li>
+</ul></li>
+<li>SOAP:
+<ul>
+ <li>Fixed WSDL cache corruption when a soap:header defines headerfaults.</li>
+ <li>Fixed stack overflow when parsing a WSDL with self-referential schema
groups or attributeGroups.</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'rgrp-mwpx-f6rm'); ?>
(Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'cj93-vc83-wgqv'); ?>
(Integer overflow to buffer overflow in SOAP HTTP parsing).
(CVE-2025-14181)</li>
+</ul></li>
+<li>Standard:
+<ul>
+ <li>Fixed a segfault when a stream filter callback unsets
StreamBucket::$data before re-attaching the bucket.</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', '7875-c8px-7q5f'); ?>
(Out-of-bounds read in the HTTP stream wrapper when following a redirect with
an empty Location header). (CVE-2026-93682)</li>
+ <li>Fixed read buffer compaction in php_stream_filter_flush().</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 22410); ?> (Incorrect float
behavior with large numbers).</li>
+ <li>Fixed <?php githubissuel('php/php-src', 23338); ?>
(fsockopen()/pfsockopen() ValueError reported wrong argument number for
$timeout).</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23576); ?> (Next index for
array returned from array_keys() is wrong).</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', '88hq-2827-7pg6'); ?>
(Out-of-bounds read in convert.* stream filters when line-break-chars contains
NUL). (CVE-2026-92842)</li>
+ <li>Fixed <?php githubsecurityl('php/php-src', 'fpwc-w8rq-cr92'); ?>
(Cross-origin credential leak in HTTP stream wrapper redirects).
(CVE-2026-91766)</li>
+</ul></li>
+<li>SimpleXML:
+<ul>
+ <li>Fixed writing to a dimension of the object returned by attributes() not
creating the attribute.</li>
+ <li>Fixed child elements of the element returned by
SimpleXMLElement::addChild() not being accessible by property name when
namespaces are involved.</li>
+</ul></li>
+<li>Windows:
+<ul>
+ <li>Fixed <?php githubsecurityl('php/php-src', '9f67-6fw4-hpfp'); ?>
(Reserved device names are not rejected before file and stream I/O).
(CVE-2026-17545)</li>
+</ul></li>
+<li>Zip:
+<ul>
+ <li>Fixed bug <?php githubissuel('php/php-src', 17787); ?> (ZipArchive
stream stops reading early when the archive is freed while the stream is still
open).</li>
+ <li>Fixed bug <?php githubissuel('php/php-src', 23276); ?> (ZipArchive
subclass storing its own stream cannot be garbage collected).</li>
+</ul></li>
+<li>SAPI:
+<ul>
+ <li>Fixed fuzzer targets failing to build in isolation.</li>
+ <li>Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo)</li>
+</ul></li>
+</ul>
+<!-- }}} --></section>
+
+
+
<section class="version" id="8.5.10"><!-- {{{ 8.5.10 -->
<h3>Version 8.5.10</h3>
<b><?php release_date('27-Aug-2026'); ?></b>
diff --git a/public/archive/archive.xml b/public/archive/archive.xml
index e6ff9e64bb..9026231161 100644
--- a/public/archive/archive.xml
+++ b/public/archive/archive.xml
@@ -9,6 +9,7 @@
<uri>http://php.net/contact</uri>
<email>[email protected]</email>
</author>
+ <xi:include href="entries/2026-09-24-3.xml"/>
<xi:include href="entries/2026-09-24-2.xml"/>
<xi:include href="entries/2026-09-24-1.xml"/>
<xi:include href="entries/2026-09-11-1.xml"/>
diff --git a/public/archive/entries/2026-09-24-3.xml
b/public/archive/entries/2026-09-24-3.xml
new file mode 100644
index 0000000000..5d96aa5eaf
--- /dev/null
+++ b/public/archive/entries/2026-09-24-3.xml
@@ -0,0 +1,21 @@
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom">
+ <title>PHP 8.5.11 Released!</title>
+ <id>https://www.php.net/archive/2026.php#2026-09-24-3</id>
+ <published>2026-09-24T11:40:51+00:00</published>
+ <updated>2026-09-24T11:40:51+00:00</updated>
+ <link href="https://www.php.net/index.php#2026-09-24-3" rel="alternate"
type="text/html"/>
+ <link href="https://www.php.net/archive/2026.php#2026-09-24-3" rel="via"
type="text/html"/>
+ <category term="releases" label="New PHP release"/>
+ <category term="frontpage" label="PHP.net frontpage news"/>
+ <content type="xhtml">
+ <div xmlns="http://www.w3.org/1999/xhtml"><p>The PHP development team
announces the immediate availability of PHP 8.5.11. This is a security
release.</p>
+
+<p>All PHP 8.5 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.5.11 please visit our <a
href="https://www.php.net/downloads.php">downloads page</a>,
+Windows source and binaries can also be found <a
href="https://www.php.net/downloads.php?os=windows&version=8.5">there</a>.
+The list of changes is recorded in the <a
href="https://www.php.net/ChangeLog-8.php#8.5.11">ChangeLog</a>.
+</p> </div>
+ </content>
+</entry>
diff --git a/public/releases/8_5_11.php b/public/releases/8_5_11.php
new file mode 100644
index 0000000000..65c99265c2
--- /dev/null
+++ b/public/releases/8_5_11.php
@@ -0,0 +1,16 @@
+<?php
+$_SERVER['BASE_PAGE'] = 'releases/8_5_11.php';
+require_once __DIR__ . '/../../include/prepend.inc';
+site_header('PHP 8.5.11 Release Announcement', ['cache' => true,
'cache_control' => 30 * 60]);
+?>
+<h1>PHP 8.5.11 Release Announcement</h1>
+
+<p>The PHP development team announces the immediate availability of PHP
8.5.11. This is a security release.</p>
+
+<p>All PHP 8.5 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.5.11 please visit our <a
href="https://www.php.net/downloads.php">downloads page</a>,
+Windows source and binaries can also be found <a
href="https://www.php.net/downloads.php?os=windows&version=8.5">there</a>.
+The list of changes is recorded in the <a
href="https://www.php.net/ChangeLog-8.php#8.5.11">ChangeLog</a>.
+</p>
+<?php site_footer();