* New upstream version 8.4.26
+ [CVE-2026-91768]: IPv6 ACL bypass in FastCGI listen.allowed_clients
due to partial address comparison.
+ [CVE-2025-1218]: Various packet overreads in mysqlnd wire protocol.
+ [CVE-2026-91769]: TLS hostname verification falls back to CN after
SAN mismatch.
+ [CVE-2026-91767]: Heap buffer overflow in
php_openssl_matches_wildcard_name() on crafted server certificate
wildcard CN.
+ [CVE-2026-6103]: Integer overflow in phar_tar_number() allowing TAR
archive entry injection.
+ [CVE-2026-91765]: Unbounded recursion in server-side
cleanup_xml_node().
+ [CVE-2025-14181]: Integer overflow to buffer overflow in SOAP HTTP
parsing.
+ [CVE-2026-93682]: Out-of-bounds read in the HTTP stream wrapper when
following a redirect with an empty Location header.
+ [CVE-2026-92842]: Out-of-bounds read in convert.* stream filters when
line-break-chars contains NUL.
+ [CVE-2026-91766]: Cross-origin credential leak in HTTP stream wrapper
redirects.
+ [CVE-2026-17545]: Reserved device names are not rejected before file
and stream I/O.