Home » Releases » 8.5 » 8.5.10 »

PHP 8.5.9

The latest release of PHP 8.5 is 8.5.10.

Source Code

  • PHP 8.5.9 (tar.gz)

    • sha256: d735459c2cbaeb0673d416c33d372d9ff261d562f6b29da48f3e6aeaeca083af
  • PHP 8.5.9 (tar.bz2)

    • sha256: 703c082ad9d2946ac647f3596812300d2c62b360d2f31a999021692a9b39476c
  • PHP 8.5.9 (tar.xz)

    • sha256: 0db7855f25bcd0ab1d592cdb35e284d6f6a5d2ae0f6f621122e364cc39b708f4

Change Log

  • core

    • Fixed bug GH-22290 (AST pretty printing does not correctly handle strings containing NUL).
      iliaal
    • Fixed bug GH-22206 (missing return in global register detection).
      P3p111n0
    • Lock unmodified readonly properties for modification after clone-with.
      NickSdot
  • bcmath

  • calendar

    • Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with INT_MAX year).
      arshidkv12
  • date

    • Update timelib to 2022.17.
      Derick
    • Fixed bug GH-19803 (Parsing a string with a single white space does create an error).
      Derick
    • Fixed Unix timestamps in February of the year 0 are misparsed with @-notation.
      LukasGelbmann
    • Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending Date classes).
      Derick
  • dba

    • Fixed OOB read on malformed length field in dba flatfile handler.
      alhudz
  • dom

    • Fixed bug GH-22570 (Stack overflow when serializing a deeply nested Dom\XMLDocument).
      iliaal
    • Fixed getElementsByClassName() item() returning the wrong element on random access.
      David Carlier
  • exif

    • Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size" warning when an IFD is not followed by a next-IFD offset).
      Eyüp Can Akman
  • gd

    • Upgrade libgd. (CVE-2026-9672)
      Pierre Joye
  • hash

    • Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc alignment).
      iliaal
  • odbc

    • Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the driver-reported display size).
      iliaal
  • opcache

    • Fixed bug GH-22158 (Tracing JIT dispatches the observer begin handler through the wrong run_time_cache slot on megamorphic calls).
      ptondereau
      iliaal
    • Fixed bug GH-22443 (Tracing JIT SIGSEGV on megamorphic dynamic calls from an undereferenced run_time_cache map_ptr offset).
      iliaal
    • Fixed bug GH-21770 (Infinite recursion in property hook getter in opcache preloaded trait).
      iliaal
  • openssl

    • Fixed timeout for supplemental read at end of a blocking stream in SSL stream wrapper.
      ilutov
  • intl

    • Fixed Locale::lookup() and locale_lookup() to return NULL instead of the fallback locale when a language tag cannot be canonicalized.
      Weilin Du
    • Fixed memory leaks when calling Collator::__construct() or Spoofchecker::__construct() twice.
      Weilin Du
    • Fixed memory leak when calling IntlListFormatter::__construct() twice.
      Weilin Du
    • Fixed IntlChar methods leaving stale global error state after successful calls.
      Xuyang Zhang
  • pdo_odbc

    • Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN carries no credentials).
      iliaal
    • Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the driver-reported display size).
      iliaal
    • Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is longer than the declared maxlen).
      iliaal
    • Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a diagnostic message length beyond the error buffer).
      iliaal
  • pgsql

    • Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543)
      ilutov
  • phar

    • Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction.
      Weilin Du
    • Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260)
      Jakub Zelenka
  • phpdbg

    • Fixed bug GH-17387 (Trivial crash in phpdbg lexer).
      iliaal
    • Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break.
      jorgsowa
    • Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to always fail during phpdbg's signal-safe interruption path.
      jorgsowa
  • reflection

    • Fixed bug GH-22324 (Ignore leading namespace separator in ReflectionParameter::__construct()).
      jorgsowa
    • Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore dynamic properties shadowing a private parent property).
      iliaal
    • Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value with null bytes truncates output).
      DanielEScherzer
    • Fixed bug GH-22683 (Reflection(Class)Constant::__toString() should not warn on NAN conversions).
      Khaled Alam
    • Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes).
      DanielEScherzer
  • session

    • Fixed bug GH-21314 (Different session garbage collector behavior between PHP 8.3 and PHP 8.5).
      jorgsowa
  • spl

    • Fix class_parents for classes with leading slash in non-autoload mode.
      jorgsowa
    • Ignore leading back-slash in class_parents(), class_implements(), and class_uses().
      jorgsowa
    • Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object segfaults).
      iliaal
  • standard

    • Fixed bug GH-22395 (base_convert() outputs at most 64 characters).
      Weilin Du
    • Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator mutates the array being sorted).
      azchin
      iliaal
  • uri

    • Fixed behavior of Uri\WhatWg\Url wither methods with regards to empty opaque hosts.
      kocsismate
    • Fixed bug GH-22628 (Percent-encoding of caret in WHATWG URL paths is not performed).
      kocsismate
    • Fixed bug GH-22629 (WHATWG Validation error incorrect with empty host and non-empty userinfo).
      kocsismate
  • zip

    • Fixed bug GH-22649 (ZipArchive::setCommentName() and setCommentIndex() could crash after overwriting an entry and resetting its inherited unchanged comment).
      Weilin Du
    • Fixed bug GH-21705 (ZipArchive::getFromIndex() ignores ZipArchive::FL_UNCHANGED for deleted entries).
      Weilin Du

PHP 8.5


  Represents a security release