* New upstream version 8.4.21
+ [CVE-2026-7263]: Dom\XMLDocument::C14N() emits duplicate xmlns
declarations after setAttributeNS()
+ [CVE-2026-29078, CVE-2026-29079]: Upgrade to lexbor v2.7.0
+ [CVE-2026-6735]: XSS within status endpoint
+ [CVE-2026-7259]: Null pointer dereference in php_mb_check_encoding()
via mb_ereg_search_init()
+ [CVE-2026-6104]: Out-of-bounds access in mbfl_name2encoding_ex()
+ [CVE-2025-14179]: SQL injection via NUL bytes in quoted strings
+ [CVE-2026-6722]: Stale SOAP_GLOBAL(ref_map) pointer with Apache Map
+ [CVE-2026-7261]: Use-after-free after header parsing failure with
SOAP_PERSISTENCE_SESSION
+ [CVE-2026-7262]: Broken Apache map value NULL check
+ [CVE-2026-7568]: Signed integer overflow of char array offset
+ [CVE-2026-7258]: Consistently pass unsigned char to ctype.h functions