Home » Releases » 8.4 » 8.4.25 »

PHP 8.4.21

The latest release of PHP 8.4 is 8.4.25 which includes important security patches.

Source Code

Change Log

  • core

    • Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors).
      iliaal
    • Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies).
      iliaal
    • Fixed bug GH-21605 (Missing addref for Countable::count()).
      ilutov
    • Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws).
      macoaure
    • Fixed bug GH-21603 (Missing addref for __unset).
      ilutov
    • Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV).
      Pratik Bhujel
  • cli

    • Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings).
      DanielEScherzer
  • curl

    • Add support for brotli and zstd on Windows.
      Shivam Mathur
  • dom

    • Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263)
      David Carlier
    • Fixed bug GH-21688 (segmentation fault on empty HTMLDocument).
      David Carlier
    • Upgrade to lexbor v2.7.0.
      CVE-2026-29078
      CVE-2026-29079) (ndossche
      ilutov
    • Fixed bug GH-21544 (Dom\XMLDocument::C14N*( drops namespace declarations on DOM-built documents).
      David Carlier
      ndossche
  • fpm

  • iconv

    • Fixed bug GH-17399 (iconv memory leak on bailout).
      iliaal
  • mbstring

    • Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259)
      vi3tL0u1s
    • Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104)
      ilutov
  • opcache

    • Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg).
      Arnaud
    • Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch).
      ilutov
    • Fixed bug GH-21460 (COND optimization regression).
      Dmitry
      Arnaud
    • Fixed faulty returns out of zend_try block in zend_jit_trace().
      ilutov
    • Fixed bug GH-21770 (Infinite recursion in property hook getter in opcache preloaded trait).
      iliaal
  • openssl

    • Fix a bunch of memory leaks and crashes on edge cases.
      ndossche
  • pdo_firebird

    • Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179)
      SakiTakamachi
  • phar

    • Restore is_link handler in phar_intercept_functions_shutdown.
      iliaal
    • Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment).
      iliaal
    • Fix memory leak in Phar::offsetGet().
      iliaal
    • Fix memory leak in phar_add_file().
      iliaal
    • Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close).
      iliaal
    • Fix memory leak in phar_verify_signature() when md_ctx is invalid.
      JarneClauw
  • random

    • Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state).
      iliaal
  • session

    • Fixed memory leak when session GC callback return a refcounted value.
      jorgsowa
  • soap

    • Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722)
      ilutov
    • Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261)
      ilutov
    • Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262)
      ilutov
  • spl

    • Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free).
      Girgias
    • Fix concurrent iteration and deletion issues in SplObjectStorage.
      ndossche
  • standard

    • Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568)
      TimWolla
    • Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258)
      ilutov
  • streams

    • Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). (CVE-2026-12184)
      ndossche
  • xsl

    • Fixed bug GH-21600 (Segfault on module shutdown).
      David Carlier
  • zip

    • Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements).
      David Carlier

PHP 8.4


  Represents a security release