Author: Pierrick Charron (adoy)
Date: 2026-09-24T09:54:45-04:00

Commit: 
https://github.com/php/web-php/commit/2cff4f1fae596e18918eb0c46a0af1a669789f1c
Raw diff: 
https://github.com/php/web-php/commit/2cff4f1fae596e18918eb0c46a0af1a669789f1c.diff

Announce PHP 8.2.34

Changed paths:
  A  public/archive/entries/2026-09-24-4.xml
  A  public/releases/8_2_34.php
  M  include/releases.inc
  M  include/version.inc
  M  public/ChangeLog-8.php
  M  public/archive/archive.xml


Diff:

diff --git a/include/releases.inc b/include/releases.inc
index 1240c43be7..b6df286cf8 100644
--- a/include/releases.inc
+++ b/include/releases.inc
@@ -2,6 +2,43 @@
 $OLDRELEASES = array (
   8 => 
   array (
+    '8.2.33' => 
+    array (
+      'announcement' => 
+      array (
+        'English' => '/releases/8_2_33.php',
+      ),
+      'tags' => 
+      array (
+        0 => 'security',
+      ),
+      'date' => '30 Jul 2026',
+      'source' => 
+      array (
+        0 => 
+        array (
+          'filename' => 'php-8.2.33.tar.gz',
+          'name' => 'PHP 8.2.33 (tar.gz)',
+          'sha256' => 
'9a525d4db1237ede408e454b46f5a93b9e45d83d71753592e3f921903d917e07',
+          'date' => '30 Jul 2026',
+        ),
+        1 => 
+        array (
+          'filename' => 'php-8.2.33.tar.bz2',
+          'name' => 'PHP 8.2.33 (tar.bz2)',
+          'sha256' => 
'5362f2a7a0e7168ce722fea0048b1a1d28e0f7cc265c417df670c65670695018',
+          'date' => '30 Jul 2026',
+        ),
+        2 => 
+        array (
+          'filename' => 'php-8.2.33.tar.xz',
+          'name' => 'PHP 8.2.33 (tar.xz)',
+          'sha256' => 
'fbdeace9b38220436a4c8fd79b900df92878151db145e641750743a283b514c1',
+          'date' => '30 Jul 2026',
+        ),
+      ),
+      'museum' => false,
+    ),
     '8.5.10' => 
     array (
       'announcement' => 
diff --git a/include/version.inc b/include/version.inc
index 5bde3043cd..e1ba94a178 100644
--- a/include/version.inc
+++ b/include/version.inc
@@ -58,13 +58,13 @@ $RELEASES = (function () {
 
     /* PHP 8.2 Release */
     $data['8.2'] = [
-        'version' => '8.2.33',
-        'date' => '30 Jul 2026',
+        'version' => '8.2.34',
+        'date' => '24 Sep 2026',
         'tags' => ['security'], // Set to ['security'] for security releases.
         'sha256' => [
-            'tar.gz' => 
'9a525d4db1237ede408e454b46f5a93b9e45d83d71753592e3f921903d917e07',
-            'tar.bz2' => 
'5362f2a7a0e7168ce722fea0048b1a1d28e0f7cc265c417df670c65670695018',
-            'tar.xz' => 
'fbdeace9b38220436a4c8fd79b900df92878151db145e641750743a283b514c1',
+            'tar.gz' => 
'b42a58817acdf3e672d497a8f5314c1ee801b4ca94ebae41878bd29cf7764105',
+            'tar.bz2' => 
'0467d63a819016811d35fd14f734764813ab149750379790634294c723cd7562',
+            'tar.xz' => 
'5351330c54de240f54f7527c26ef292e239749e6fe11db0330acb5317e02bb39',
         ]
     ];
 
diff --git a/public/ChangeLog-8.php b/public/ChangeLog-8.php
index 69ffa75d2a..33deec6b0b 100644
--- a/public/ChangeLog-8.php
+++ b/public/ChangeLog-8.php
@@ -6861,6 +6861,50 @@
 
 <a id="PHP_8_2"></a>
 
+<section class="version" id="8.2.34"><!-- {{{ 8.2.34 -->
+<h3>Version 8.2.34</h3>
+<b><?php release_date('24-Sep-2026'); ?></b>
+<ul><li>Filter:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'ch8v-r6jh-4vvr'); ?> 
(FILTER_SANITIZE_ENCODED does not encode 0xFF).</li>
+</ul></li>
+<li>FPM:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', '62xp-839h-2637'); ?> (IPv6 
ACL bypass in FastCGI listen.allowed_clients due to partial address 
comparison). (CVE-2026-91768)</li>
+</ul></li>
+<li>MySQLnd:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'r6x9-5r99-36j7'); ?> 
(Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218)</li>
+</ul></li>
+<li>OpenSSL:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'vvx9-73fr-5jjx'); ?> (TLS 
hostname verification falls back to CN after SAN mismatch). 
(CVE-2026-91769)</li>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'xr7j-rvgx-xq5p'); ?> (Heap 
buffer overflow in php_openssl_matches_wildcard_name() on crafted server 
certificate wildcard CN). (CVE-2026-91767)</li>
+</ul></li>
+<li>Phar:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'j3wh-g957-2m85'); ?> 
(Integer overflow in phar_tar_number() allowing TAR archive entry injection). 
(CVE-2026-6103)</li>
+</ul></li>
+<li>SOAP:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'rgrp-mwpx-f6rm'); ?> 
(Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765)</li>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'cj93-vc83-wgqv'); ?> 
(Integer overflow to buffer overflow in SOAP HTTP parsing). 
(CVE-2025-14181)</li>
+</ul></li>
+<li>Standard:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', '88hq-2827-7pg6'); ?> 
(Out-of-bounds read in convert.* stream filters when line-break-chars contains 
NUL). (CVE-2026-92842)</li>
+  <li>Fixed <?php githubsecurityl('php/php-src', 'fpwc-w8rq-cr92'); ?> 
(Cross-origin credential leak in HTTP stream wrapper redirects). 
(CVE-2026-91766)</li>
+  <li>Fixed <?php githubsecurityl('php/php-src', '7875-c8px-7q5f'); ?> 
(Out-of-bounds read in the HTTP stream wrapper when following a redirect with 
an empty Location header). (CVE-2026-93682)</li>
+</ul></li>
+<li>Windows:
+<ul>
+  <li>Fixed <?php githubsecurityl('php/php-src', '9f67-6fw4-hpfp'); ?> 
(Reserved device names are not rejected before file and stream I/O). 
(CVE-2026-17545)</li>
+</ul></li>
+</ul>
+<!-- }}} --></section>
+
+
+
 <section class="version" id="8.2.33"><!-- {{{ 8.2.33 -->
 <h3>Version 8.2.33</h3>
 <b><?php release_date('30-Jul-2026'); ?></b>
diff --git a/public/archive/archive.xml b/public/archive/archive.xml
index 9026231161..d571efbb19 100644
--- a/public/archive/archive.xml
+++ b/public/archive/archive.xml
@@ -9,6 +9,7 @@
     <uri>http://php.net/contact</uri>
     <email>[email protected]</email>
   </author>
+  <xi:include href="entries/2026-09-24-4.xml"/>
   <xi:include href="entries/2026-09-24-3.xml"/>
   <xi:include href="entries/2026-09-24-2.xml"/>
   <xi:include href="entries/2026-09-24-1.xml"/>
diff --git a/public/archive/entries/2026-09-24-4.xml 
b/public/archive/entries/2026-09-24-4.xml
new file mode 100644
index 0000000000..e38fffa71c
--- /dev/null
+++ b/public/archive/entries/2026-09-24-4.xml
@@ -0,0 +1,21 @@
+<?xml version="1.0" encoding="utf-8"?>
+<entry xmlns="http://www.w3.org/2005/Atom";>
+  <title>PHP 8.2.34 Released!</title>
+  <id>https://www.php.net/archive/2026.php#2026-09-24-4</id>
+  <published>2026-09-24T13:53:04+00:00</published>
+  <updated>2026-09-24T13:53:04+00:00</updated>
+  <link href="https://www.php.net/index.php#2026-09-24-4"; rel="alternate" 
type="text/html"/>
+  <link href="https://www.php.net/archive/2026.php#2026-09-24-4"; rel="via" 
type="text/html"/>
+  <category term="releases" label="New PHP release"/>
+  <category term="frontpage" label="PHP.net frontpage news"/>
+  <content type="xhtml">
+    <div xmlns="http://www.w3.org/1999/xhtml";><p>The PHP development team 
announces the immediate availability of PHP 8.2.34. This is a security 
release.</p>
+
+<p>All PHP 8.2 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.2.34 please visit our <a 
href="https://www.php.net/downloads.php";>downloads page</a>,
+Windows source and binaries can also be found <a 
href="https://www.php.net/downloads.php?os=windows&amp;version=8.2";>there</a>.
+The list of changes is recorded in the <a 
href="https://www.php.net/ChangeLog-8.php#8.2.34";>ChangeLog</a>.
+</p>    </div>
+  </content>
+</entry>
diff --git a/public/releases/8_2_34.php b/public/releases/8_2_34.php
new file mode 100644
index 0000000000..68c934c6bd
--- /dev/null
+++ b/public/releases/8_2_34.php
@@ -0,0 +1,16 @@
+<?php
+$_SERVER['BASE_PAGE'] = 'releases/8_2_34.php';
+require_once __DIR__ . '/../../include/prepend.inc';
+site_header('PHP 8.2.34 Release Announcement', ['cache' => true, 
'cache_control' => 30 * 60]);
+?>
+<h1>PHP 8.2.34 Release Announcement</h1>
+
+<p>The PHP development team announces the immediate availability of PHP 
8.2.34. This is a security release.</p>
+
+<p>All PHP 8.2 users are encouraged to upgrade to this version.</p>
+
+<p>For source downloads of PHP 8.2.34 please visit our <a 
href="https://www.php.net/downloads.php";>downloads page</a>,
+Windows source and binaries can also be found <a 
href="https://www.php.net/downloads.php?os=windows&amp;version=8.2";>there</a>.
+The list of changes is recorded in the <a 
href="https://www.php.net/ChangeLog-8.php#8.2.34";>ChangeLog</a>.
+</p>
+<?php site_footer();

Reply via email to