{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2019-9023: complete the heap-based buffer over-read fix in the mbstring\n  regular expression functions for invalid multibyte data; the backport carried\n  by Patch873/Patch875/Patch1011 was taken from the PHP-7.3.1 cumulative and was\n  missing two of the upstream code changes. Add the php.net bug #77370 clamp to\n  the regparse.c pattern-scanner macros (PINC/PFETCH, the oniguruma 4.7.1\n  equivalents of upstream's PFETCH/PINC_S/PFETCH_S) so a truncated multibyte\n  sequence at the end of a pattern can no longer leave the cursor past the\n  buffer end, plus the upstream reproducer ext/mbstring/tests/bug77370.phpt; and\n  add the case-folding clamp from the bug #77381/#77382/#77385/#77394 commit to\n  the five Unicode *_mbc_to_normalize() implementations in\n  ext/mbstring/oniguruma/enc/ (utf8, utf16_be, utf16_le, utf32_be, utf32_le),\n  which are oniguruma 4.7.1's equivalent of upstream's\n  onigenc_unicode_mbc_case_fold(), so a case-insensitive mb_ereg()/mb_split()\n  pattern ending in a truncated multibyte sequence no longer copies more bytes\n  than the buffer holds\n- CVE-2019-9641: integer overflows in the EXIF extension on 32-bit builds\n  leading to an uninitialized read (php.net bug #77509). Backport upstream\n  commit 5e824a88d073d282c4f358f186cb87ddc284f83d: exif_process_IFD_in_TIFF()\n  added the directory size, the IFD size and a constant 2 to the\n  attacker-controlled directory offset before comparing the sums against the\n  file size, so a crafted TIFF could wrap the sums, pass the checks and have\n  php_ifd_get16u() read from the still-uninitialized section buffer. The\n  additions are rewritten as subtractions from the file size, which cannot\n  overflow, and num_entries is widened to size_t before being scaled by 12",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
        "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_php/el10/advisories/2026/clsa-2026_1788355303.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-02T13:26:14Z",
      "generator": {
        "date": "2026-09-02T13:26:14Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788355303",
      "initial_release_date": "2026-09-02T13:26:14Z",
      "revision_history": [
        {
          "date": "2026-09-02T13:26:14Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "alt-php54: Fix of 31 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 10",
                "product": {
                  "name": "Community Enterprise Operating System 10",
                  "product_id": "CentOS-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-php-fpm@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-firebird-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-firebird-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-firebird-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-firebird@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-mcrypt@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-pgsql@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-mysqlnd@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-snmp-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-snmp-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-snmp-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-snmp@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-soap-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-soap-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-soap-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-soap@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-imap-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-imap-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-imap-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-imap@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-gd-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-gd-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-gd-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-gd@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-mbstring@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-odbc-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-odbc-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-odbc-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-odbc@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-bcmath@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-pspell-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-pspell-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-pspell-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-pspell@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-devel-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-devel-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-devel-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-devel@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-ldap-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-ldap-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-ldap-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-ldap@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-process-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-process-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-process-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-process@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-dba-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-dba-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-dba-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-dba@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-xml-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-xml-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-xml-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-xml@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-recode-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-recode-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-recode-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-recode@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-xmlrpc@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-intl-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-intl-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-intl-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-intl@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-tidy-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-tidy-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-tidy-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-tidy@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-cli-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-cli-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-cli-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-cli@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-dbx-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-dbx-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-dbx-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-dbx@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-enchant-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-enchant-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-enchant-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-enchant@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-common-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-common-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-common-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-common@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-sybase-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-sybase-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-sybase-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-sybase@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-mssql-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-mssql-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-mssql-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-mssql@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-php54-pdo-0:5.4.45-192.el10.x86_64",
                "product": {
                  "name": "alt-php54-pdo-0:5.4.45-192.el10.x86_64",
                  "product_id": "alt-php54-pdo-0:5.4.45-192.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-php54-pdo@5.4.45-192.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-php-fpm-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-firebird-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-firebird-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-mcrypt-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-pgsql-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-snmp-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-snmp-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-soap-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-soap-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-imap-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-imap-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-gd-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-gd-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-mbstring-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-odbc-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-odbc-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-bcmath-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-pspell-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-pspell-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-devel-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-devel-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-ldap-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-ldap-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-process-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-process-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-dba-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-dba-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-xml-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-xml-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-recode-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-recode-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-intl-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-intl-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-tidy-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-tidy-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-cli-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-cli-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-dbx-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-dbx-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-enchant-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-enchant-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-common-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-common-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-sybase-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-sybase-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-mssql-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-mssql-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-php54-pdo-0:5.4.45-192.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64"
        },
        "product_reference": "alt-php54-pdo-0:5.4.45-192.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-7071",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2020-7071"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77423",
          "url": "https://bugs.php.net/bug.php?id=77423"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2021/07/msg00008.html",
          "url": "https://lists.debian.org/debian-lts-announce/2021/07/msg00008.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202105-23",
          "url": "https://security.gentoo.org/glsa/202105-23"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20210312-0005/",
          "url": "https://security.netapp.com/advisory/ntap-20210312-0005/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2021/dsa-4856",
          "url": "https://www.debian.org/security/2021/dsa-4856"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpuoct2021.html",
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2021-02-15T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2022-31629",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2022-31629"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2024/04/12/11",
          "url": "http://www.openwall.com/lists/oss-security/2024/04/12/11"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=81727",
          "url": "https://bugs.php.net/bug.php?id=81727"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSJVPJTX7T3J5V7XHR4MFNHZGP44R5XE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSJVPJTX7T3J5V7XHR4MFNHZGP44R5XE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202211-03",
          "url": "https://security.gentoo.org/glsa/202211-03"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20221209-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20221209-0001/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5277",
          "url": "https://www.debian.org/security/2022/dsa-5277"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/"
        }
      ],
      "release_date": "2022-09-28T23:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-3824",
      "cwe": {
        "id": "CWE-119",
        "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2023-3824"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-jqcx-ccgc-xwhv",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-jqcx-ccgc-xwhv"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/09/msg00002.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00002.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7NBF77WN6DTVTY2RE73IGPYD6M4PIAWA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7NBF77WN6DTVTY2RE73IGPYD6M4PIAWA/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230825-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20230825-0001/"
        }
      ],
      "release_date": "2023-08-11T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2019-9641",
      "cwe": {
        "id": "CWE-908",
        "name": "Use of Uninitialized Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-9641"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77509",
          "url": "https://bugs.php.net/bug.php?id=77509"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190502-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20190502-0007/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3922-1/",
          "url": "https://usn.ubuntu.com/3922-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3922-2/",
          "url": "https://usn.ubuntu.com/3922-2/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3922-3/",
          "url": "https://usn.ubuntu.com/3922-3/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4403",
          "url": "https://www.debian.org/security/2019/dsa-4403"
        }
      ],
      "release_date": "2019-03-09T00:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2019-11036",
      "cwe": {
        "id": "CWE-126",
        "name": "Buffer Over-read"
      },
      "notes": [
        {
          "category": "description",
          "text": "When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-11036"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00010.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00010.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/108177",
          "url": "http://www.securityfocus.com/bid/108177"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:2519",
          "url": "https://access.redhat.com/errata/RHSA-2019:2519"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3299",
          "url": "https://access.redhat.com/errata/RHSA-2019:3299"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77950",
          "url": "https://bugs.php.net/bug.php?id=77950"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/05/msg00035.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00035.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NFXYNCXZCPYT7ZN4ZLI5EPQQW44FRRO/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NFXYNCXZCPYT7ZN4ZLI5EPQQW44FRRO/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BY2XUUAN277LS7HKAOGL4DVGAELOJV3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BY2XUUAN277LS7HKAOGL4DVGAELOJV3/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WN2HLPGEZEF4MFM5YC5FILZB5QEQFP3A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WN2HLPGEZEF4MFM5YC5FILZB5QEQFP3A/"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2019/Sep/35",
          "url": "https://seclists.org/bugtraq/2019/Sep/35"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2019/Sep/38",
          "url": "https://seclists.org/bugtraq/2019/Sep/38"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190517-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20190517-0003/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3566-2/",
          "url": "https://usn.ubuntu.com/3566-2/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4009-1/",
          "url": "https://usn.ubuntu.com/4009-1/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4527",
          "url": "https://www.debian.org/security/2019/dsa-4527"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4529",
          "url": "https://www.debian.org/security/2019/dsa-4529"
        }
      ],
      "release_date": "2019-05-03T20:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-1217",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2025-1217"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250523-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20250523-0008/"
        }
      ],
      "release_date": "2025-03-29T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2026-14355",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-14355"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html",
          "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html"
        }
      ],
      "release_date": "2026-07-03T21:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-6735",
      "cwe": {
        "id": "CWE-79",
        "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-6735"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv"
        }
      ],
      "release_date": "2026-05-10T05:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2019-11047",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-11047"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=78910",
          "url": "https://bugs.php.net/bug.php?id=78910"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2020/Feb/27",
          "url": "https://seclists.org/bugtraq/2020/Feb/27"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2020/Feb/31",
          "url": "https://seclists.org/bugtraq/2020/Feb/31"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2021/Jan/3",
          "url": "https://seclists.org/bugtraq/2021/Jan/3"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20200103-0002/",
          "url": "https://security.netapp.com/advisory/ntap-20200103-0002/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4239-1/",
          "url": "https://usn.ubuntu.com/4239-1/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4626",
          "url": "https://www.debian.org/security/2020/dsa-4626"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4628",
          "url": "https://www.debian.org/security/2020/dsa-4628"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2019-12-23T03:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2021-21705",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2021-21705"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=81122",
          "url": "https://bugs.php.net/bug.php?id=81122"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202209-20",
          "url": "https://security.gentoo.org/glsa/202209-20"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20211029-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20211029-0006/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujan2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
        }
      ],
      "release_date": "2021-10-04T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-1861",
      "cwe": {
        "id": "CWE-131",
        "name": "Incorrect Calculation of Buffer Size"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2025-1861"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250523-0005/",
          "url": "https://security.netapp.com/advisory/ntap-20250523-0005/"
        }
      ],
      "release_date": "2025-03-30T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-8925",
      "cwe": {
        "id": "CWE-444",
        "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2024-8925"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241101-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20241101-0003/"
        }
      ],
      "release_date": "2024-10-08T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-6491",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2025-6491"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/07/11/4",
          "url": "http://www.openwall.com/lists/oss-security/2025/07/11/4"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html"
        }
      ],
      "release_date": "2025-07-13T22:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2019-9023",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring/oniguruma/regparse.c, ext/mbstring/oniguruma/enc/unicode.c, and ext/mbstring/oniguruma/src/utf32_be.c when a multibyte regular expression pattern contains invalid multibyte sequences.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-9023"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/107156",
          "url": "http://www.securityfocus.com/bid/107156"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:2519",
          "url": "https://access.redhat.com/errata/RHSA-2019:2519"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3299",
          "url": "https://access.redhat.com/errata/RHSA-2019:3299"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77370",
          "url": "https://bugs.php.net/bug.php?id=77370"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77371",
          "url": "https://bugs.php.net/bug.php?id=77371"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77381",
          "url": "https://bugs.php.net/bug.php?id=77381"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77382",
          "url": "https://bugs.php.net/bug.php?id=77382"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77385",
          "url": "https://bugs.php.net/bug.php?id=77385"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77394",
          "url": "https://bugs.php.net/bug.php?id=77394"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=77418",
          "url": "https://bugs.php.net/bug.php?id=77418"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190321-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20190321-0001/"
        },
        {
          "category": "external",
          "summary": "https://support.f5.com/csp/article/K06372014",
          "url": "https://support.f5.com/csp/article/K06372014"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3902-1/",
          "url": "https://usn.ubuntu.com/3902-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3902-2/",
          "url": "https://usn.ubuntu.com/3902-2/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4398",
          "url": "https://www.debian.org/security/2019/dsa-4398"
        }
      ],
      "release_date": "2019-02-22T23:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2020-7068",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2020-7068"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=79797",
          "url": "https://bugs.php.net/bug.php?id=79797"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202009-10",
          "url": "https://security.gentoo.org/glsa/202009-10"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20200918-0005/",
          "url": "https://security.netapp.com/advisory/ntap-20200918-0005/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2021/dsa-4856",
          "url": "https://www.debian.org/security/2021/dsa-4856"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2020-09-09T18:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2019-11043",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-11043"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html"
        },
        {
          "category": "external",
          "summary": "http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html",
          "url": "http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2020/Jan/40",
          "url": "http://seclists.org/fulldisclosure/2020/Jan/40"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3286",
          "url": "https://access.redhat.com/errata/RHSA-2019:3286"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3287",
          "url": "https://access.redhat.com/errata/RHSA-2019:3287"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3299",
          "url": "https://access.redhat.com/errata/RHSA-2019:3299"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3300",
          "url": "https://access.redhat.com/errata/RHSA-2019:3300"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3724",
          "url": "https://access.redhat.com/errata/RHSA-2019:3724"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3735",
          "url": "https://access.redhat.com/errata/RHSA-2019:3735"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3736",
          "url": "https://access.redhat.com/errata/RHSA-2019:3736"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2020:0322",
          "url": "https://access.redhat.com/errata/RHSA-2020:0322"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=78599",
          "url": "https://bugs.php.net/bug.php?id=78599"
        },
        {
          "category": "external",
          "summary": "https://github.com/neex/phuip-fpizdam",
          "url": "https://github.com/neex/phuip-fpizdam"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2020/Jan/44",
          "url": "https://seclists.org/bugtraq/2020/Jan/44"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20191031-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20191031-0003/"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/kb/HT210919",
          "url": "https://support.apple.com/kb/HT210919"
        },
        {
          "category": "external",
          "summary": "https://support.f5.com/csp/article/K75408500?utm_source=f5support&amp%3Butm_medium=RSS",
          "url": "https://support.f5.com/csp/article/K75408500?utm_source=f5support&amp%3Butm_medium=RSS"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4166-1/",
          "url": "https://usn.ubuntu.com/4166-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4166-2/",
          "url": "https://usn.ubuntu.com/4166-2/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4552",
          "url": "https://www.debian.org/security/2019/dsa-4552"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2019/dsa-4553",
          "url": "https://www.debian.org/security/2019/dsa-4553"
        },
        {
          "category": "external",
          "summary": "https://www.synology.com/security/advisory/Synology_SA_19_36",
          "url": "https://www.synology.com/security/advisory/Synology_SA_19_36"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043"
        }
      ],
      "release_date": "2019-10-28T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-2756",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "Due to an incomplete fix to  CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2024-2756"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2024/04/12/11",
          "url": "http://www.openwall.com/lists/oss-security/2024/04/12/11"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5j-x4v4",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5j-x4v4"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240510-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20240510-0008/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/"
        }
      ],
      "release_date": "2024-04-29T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2024-11236",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2024-11236"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-5hqh-c84r-qjcv",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-5hqh-c84r-qjcv"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241220-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20241220-0008/"
        }
      ],
      "release_date": "2024-11-24T01:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-1220",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2025-1220"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/07/11/4",
          "url": "http://www.openwall.com/lists/oss-security/2025/07/11/4"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/07/msg00017.html"
        }
      ],
      "release_date": "2025-07-13T23:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-7261",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-7261"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q"
        }
      ],
      "release_date": "2026-05-10T05:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-8929",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2024-8929"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250110-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20250110-0008/"
        }
      ],
      "release_date": "2024-11-22T07:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2022-31628",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress \"quines\" gzip files, resulting in an infinite loop.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2022-31628"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=81726",
          "url": "https://bugs.php.net/bug.php?id=81726"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202211-03",
          "url": "https://security.gentoo.org/glsa/202211-03"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20221209-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20221209-0001/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5277",
          "url": "https://www.debian.org/security/2022/dsa-5277"
        }
      ],
      "release_date": "2022-09-28T23:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2019-11045",
      "cwe": {
        "id": "CWE-170",
        "name": "Improper Null Termination"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \\0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2019-11045"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=78863",
          "url": "https://bugs.php.net/bug.php?id=78863"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2020/Feb/27",
          "url": "https://seclists.org/bugtraq/2020/Feb/27"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2020/Feb/31",
          "url": "https://seclists.org/bugtraq/2020/Feb/31"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2021/Jan/3",
          "url": "https://seclists.org/bugtraq/2021/Jan/3"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20200103-0002/",
          "url": "https://security.netapp.com/advisory/ntap-20200103-0002/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4239-1/",
          "url": "https://usn.ubuntu.com/4239-1/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4626",
          "url": "https://www.debian.org/security/2020/dsa-4626"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4628",
          "url": "https://www.debian.org/security/2020/dsa-4628"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2019-12-23T03:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-6722",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-6722"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:22142",
          "url": "https://access.redhat.com/errata/RHSA-2026:22142"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:22143",
          "url": "https://access.redhat.com/errata/RHSA-2026:22143"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:22305",
          "url": "https://access.redhat.com/errata/RHSA-2026:22305"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:22649",
          "url": "https://access.redhat.com/errata/RHSA-2026:22649"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:23388",
          "url": "https://access.redhat.com/errata/RHSA-2026:23388"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:33449",
          "url": "https://access.redhat.com/errata/RHSA-2026:33449"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:34354",
          "url": "https://access.redhat.com/errata/RHSA-2026:34354"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-6722",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6722"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2468560",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468560"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6722.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6722.json"
        }
      ],
      "release_date": "2026-05-10T05:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-17543",
      "cwe": {
        "id": "CWE-89",
        "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-17543"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4"
        }
      ],
      "release_date": "2026-07-30T12:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2022-31631",
      "cwe": {
        "id": "CWE-74",
        "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2022-31631"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=81740",
          "url": "https://bugs.php.net/bug.php?id=81740"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230223-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20230223-0007/"
        }
      ],
      "release_date": "2025-02-12T22:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-7260",
      "cwe": {
        "id": "CWE-121",
        "name": "Stack-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2026-7260"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3"
        }
      ],
      "release_date": "2026-07-30T12:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2020-7066",
      "cwe": {
        "id": "CWE-170",
        "name": "Improper Null Termination"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2020-7066"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00025.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00025.html"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=79329",
          "url": "https://bugs.php.net/bug.php?id=79329"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/04/msg00021.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/04/msg00021.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20200403-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20200403-0001/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4330-2/",
          "url": "https://usn.ubuntu.com/4330-2/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4717",
          "url": "https://www.debian.org/security/2020/dsa-4717"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4719",
          "url": "https://www.debian.org/security/2020/dsa-4719"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2020-04-01T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-3247",
      "cwe": {
        "id": "CWE-252",
        "name": "Unchecked Return Value"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could lead to a disclosure of 31 bits of uninitialized memory from the client to the server, and it also made easier to a malicious server to guess the client's nonce. \n\n",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2023-3247"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw"
        }
      ],
      "release_date": "2023-07-22T05:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-1734",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2025-1734"
        },
        {
          "category": "external",
          "summary": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44",
          "url": "https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00014.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250523-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20250523-0009/"
        }
      ],
      "release_date": "2025-03-30T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2020-7063",
      "cwe": {
        "id": "CWE-281",
        "name": "Improper Preservation of Permissions"
      },
      "notes": [
        {
          "category": "description",
          "text": "In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
          "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-php/cve/CVE-2020-7063"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html"
        },
        {
          "category": "external",
          "summary": "https://bugs.php.net/bug.php?id=79082",
          "url": "https://bugs.php.net/bug.php?id=79082"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/03/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/03/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202003-57",
          "url": "https://security.gentoo.org/glsa/202003-57"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4330-1/",
          "url": "https://usn.ubuntu.com/4330-1/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4717",
          "url": "https://www.debian.org/security/2020/dsa-4717"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2020/dsa-4719",
          "url": "https://www.debian.org/security/2020/dsa-4719"
        },
        {
          "category": "external",
          "summary": "https://www.tenable.com/security/tns-2021-14",
          "url": "https://www.tenable.com/security/tns-2021-14"
        }
      ],
      "release_date": "2020-02-27T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T13:21:45.856485Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303",
          "product_ids": [
            "CentOS-10:alt-php54-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-bcmath-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-cli-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-common-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dba-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-dbx-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-devel-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-enchant-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-firebird-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-gd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-imap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-intl-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-ldap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mbstring-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mcrypt-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mssql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-mysqlnd-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-odbc-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pdo-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pgsql-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-php-fpm-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-process-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-pspell-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-recode-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-snmp-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-soap-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-sybase-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-tidy-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xml-0:5.4.45-192.el10.x86_64",
            "CentOS-10:alt-php54-xmlrpc-0:5.4.45-192.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-php/releases/CLSA-2026:1788355303"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}