Release date:
2026-05-15 10:16:11 UTC
Description:
- CVE-2026-6735: HTML-encode proc.request_uri and tighten query_string
entity flags in sapi/fpm/fpm/fpm_status.c to fix XSS in PHP-FPM status
endpoint
Updated packages:
-
php-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:32d0af50d874ea4416880f8104a60fc78a84a2cf75aee5bf028897e9eb588c70
-
php-bcmath-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:cfc8305a230ef1b351406b4a08232dca0f7fbfdea30d5d93f1de94b804a460c0
-
php-cli-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:56752afa059770a3d5298da88df6531fda0dcd567cf3b92f584c57efb6096212
-
php-common-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:42708618847d4b8c3311bef621d0415c7863e2947b557b211c1c178ab183b31a
-
php-dba-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:0739597aa74de8a90df3ea58020d32b13b9f5d3943d8d35c40598ef703543f75
-
php-dbg-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:456e84d8cb7b18f208bd3045470b538ecb86a898691ec1f656cc6ed395c08378
-
php-devel-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:67cfd9e06ef76050a60b800573e0e220ca436ca33657c2d052666653145ef941
-
php-embedded-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:a7f5eb5565b80ad816a6241226ae79270753e4a899b4c4e0353c5b41d3c3b377
-
php-enchant-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:35b4db3ab47d73b9c0cd44edbde52e02dc773d9135a93e9e91c88ec3129e68fb
-
php-ffi-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:e4a1e982eb3029c22874bbf8fdcf949ad38a0d5cdbffbda92e7db07af5d13cab
-
php-fpm-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:7d1f3dd1e9e582833fcfa490e66a3d7dc198589a7edfff5be13ef621ec6c8b58
-
php-gd-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:eb51a4a03ef38898d6ce6a43bb98481189a4c53045606c1231dc51fddef7fc74
-
php-gmp-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:96ad7e7006af4cadc6f522c970de34522da32ea4d8795340fd9bd3d57a2b8a14
-
php-intl-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:745c777a8430b4f69d9bd49453837f1c54e6c375c73795ce53459a388c9db430
-
php-json-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:8c791522ac7c6ba1d7824e53bf18ce4653295795f2cd0ed464dfd93f44dc1038
-
php-ldap-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:1a6c0864310603edbf3c8b753c200b2955a8c22c4cc31c8f7ddccce913aedc3d
-
php-mbstring-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:7c301efd59db04dd0bfff5ad899396b5702096835715df8bb7bec20385b6c12c
-
php-mysqlnd-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:bb2df877a4e322d800a5a76693ec79dbef6e0b0b0bef63fed0e0619729686aa2
-
php-odbc-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:0b08fb9e0566cecf1d1a676c67e6674f1d73a6adcf9070d55315db699704f120
-
php-opcache-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:e9d39554bbd9b7cebb13e0e72f1698df5249e762ca090f988a283c461fb9994e
-
php-pdo-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:30718ce208ec58ca86f01177aec61e0ea72082e45e4333bed46e8d06469d6c47
-
php-pgsql-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:b359f0cbac9a138d792721911eee84837a7d8d1a547410dab49e21c127b0e8f4
-
php-process-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:d27c0f97a437f1a47f0a6c528dc8cf290871d0f9d80abe1ccbe2d409d896cdaa
-
php-snmp-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:d514322d8c9656bb355eae86fc094e666c675038dd8a32bb154fee53b6f1fe43
-
php-soap-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:28bebdfc86be5935b01595bdae64ebb2ff8e9d55283946cc6235b03cbc0eb45b
-
php-xml-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:a8757dd4335ae128f980c1df7c78616f6c5b89a33793887a83cf01c5c63dd968
-
php-xmlrpc-7.4.19-1.module_el8.5.0+2402+92e54353.tuxcare.els26.x86_64.rpm
sha:67d83ef49a32d73dd26e8c08b260bf5853886e7994a043cbe99d96177647d23a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.