Home » Releases » 7.4 » 7.4.33 »

PHP 7.4.21

PHP 7.4 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 7.4 is 7.4.33 which includes important security patches.

Source Code

Change Log

  • core

    • Fixed bug #76359 (open_basedir bypass through adding "..").
      cmb
    • Fixed bug #81068 (Double free in realpath_cache_clean()).
      Dimitry Andric
    • Fixed bug #81070 (Integer underflow in memory limit comparison).
      Peter van Dommelen
    • Fixed bug #81090 (Typed property performance degradation with .= operator).
      Nikita
    • Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705)
      cmb
  • bzip2

    • Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
      cmb
  • openssl

    • Fixed bug #76694 (native Windows cert verification uses CN as sever name).
      cmb
  • pdo_firebird

    • Fixed bug #76448: Stack buffer overflow in firebird_info_cb. (CVE-2021-21704)
      cmb
    • Fixed bug #76449: SIGSEGV in firebird_handle_doer. (CVE-2021-21704)
      cmb
    • Fixed bug #76450: SIGSEGV in firebird_stmt_execute. (CVE-2021-21704)
      cmb
    • Fixed bug #76452: Crash while parsing blob data in firebird_fetch_blob. (CVE-2021-21704)
      cmb
  • standard

    • Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string conversion").
      cmb

PHP 7.4


  Represents a security release