Skip to content

Commit 4040583

Browse files
Sync Collecting Fix Commits: Mon Aug 3 18:57:04 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent e525824 commit 4040583

9 files changed

Lines changed: 82 additions & 38 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 44 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,50 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-FXQJ-RQCC-2CMP": {
5+
"819fcf145fb3eb71cb00302bb448f2ecc514b746": "Publish GHSA-fxqj-rqcc-2cmp"
6+
},
7+
"GHSA-RGW5-RVV9-X895": {
8+
"93d3071ac921390f2c1c9361a7023b3e513008d5": "Publish GHSA-rgw5-rvv9-x895"
9+
},
10+
"GHSA-JJ27-H5HQ-8X99": {
11+
"a2a742050f04ce38d1f296eafec4c0c4c2b264de": "Publish GHSA-jj27-h5hq-8x99"
12+
},
13+
"GHSA-VPX6-8PJR-4G3V": {
14+
"f3f04e8bdc9cee9ed4085136a5bf9a07eecfe5ef": "Publish GHSA-vpx6-8pjr-4g3v"
15+
},
16+
"GHSA-JHPW-976M-542J": {
17+
"46607b227c021165a7ff5ec0ee2c81ccd8812b8a": "Publish GHSA-jhpw-976m-542j"
18+
},
19+
"GHSA-M65R-RPRJ-R5RG": {
20+
"ccc5d227142d52d6a4e487116d305602aa4777a8": "Publish GHSA-m65r-rprj-r5rg"
21+
},
22+
"GHSA-QWWW-VCR4-C8H2": {
23+
"95e2e1d18f4940050a3bb0fbab29f158c4013f9a": "Improve GHSA-qwww-vcr4-c8h2",
24+
"814da1e207af0d318858cfd3858002a56225926d": "Improve GHSA-qwww-vcr4-c8h2",
25+
"76c676188ecfde3b1711d69cf6348b93d71e1d2c": "Improve GHSA-qwww-vcr4-c8h2",
26+
"2de80c26b06c5824ac16f1d5af183e56e486e236": "Improve GHSA-qwww-vcr4-c8h2",
27+
"cd4ee71ce402a4cc78c69988fda1f117c1b64279": "Improve GHSA-qwww-vcr4-c8h2",
28+
"5d6e1e252e6125527d2d29377e6a5c9954dc252f": "Improve GHSA-qwww-vcr4-c8h2",
29+
"4da50480fc88ef6733f73e6cd547ac92f613a0e5": "Improve GHSA-qwww-vcr4-c8h2",
30+
"02ed867ff3261d2dfdd27361617c9d5be6cc80f0": "Publish Advisories\n\nGHSA-464c-974j-9xm6\nGHSA-5xvq-cp9x-6p6r\nGHSA-83w8-p2f5-377r\nGHSA-8pvw-jcv7-9cmj\nGHSA-qwww-vcr4-c8h2\nGHSA-r9mr-m37c-5fr3"
31+
},
32+
"GHSA-2R2C-CX56-8933": {
33+
"073e611e4ca245277243eb6d55dfd7e60af18fab": "Improve GHSA-2r2c-cx56-8933",
34+
"ffcf09d2985f26ec684f757049278a4b9426a47f": "Improve GHSA-2r2c-cx56-8933",
35+
"a98ecc0a2017806af2e68e480b70154156d9c756": "Publish Advisories\n\nGHSA-7pr5-w74r-jjj7\nGHSA-2r2c-cx56-8933\nGHSA-3h6h-67x3-cv5x\nGHSA-3wrr-7qpf-2prh\nGHSA-47qp-hqvx-6r3f\nGHSA-4w6r-5c2j-qf5f\nGHSA-52fw-7fw2-fmv5\nGHSA-5hh8-q8hv-fr38\nGHSA-6mhr-74x2-98v9\nGHSA-9fxm-vc8v-hj55\nGHSA-g72g-r7m4-9x4g\nGHSA-gprh-27j3-g5h4\nGHSA-h6vv-pcq8-7xm4\nGHSA-hgj6-7826-r7m5\nGHSA-hmcr-rmjq-47qr\nGHSA-j3rv-43j4-c7qm\nGHSA-r989-7g3j-wjhw\nGHSA-rcqc-6cw3-h962\nGHSA-rmj7-2vxq-3g9f\nGHSA-g796-fgmg-93mv",
36+
"3fdade359a569c7904e212331250ace917aff918": "Publish Advisories\n\nGHSA-2c85-rfcc-g74j\nGHSA-2r2c-cx56-8933\nGHSA-2vcc-5v34-9jc8\nGHSA-47qp-hqvx-6r3f\nGHSA-64mm-vxmg-q3vj\nGHSA-6x8v-2fq5-2229\nGHSA-94jp-7776-qj6q\nGHSA-gcq2-9pq2-cxqm"
37+
},
38+
"GHSA-47QP-HQVX-6R3F": {
39+
"d20c5e8f1c60d98992daac422eafe5384b5c1978": "Improve GHSA-47qp-hqvx-6r3f",
40+
"8e006d478bda57c4db78c71461a9fa0bba93e500": "Improve GHSA-47qp-hqvx-6r3f",
41+
"a98ecc0a2017806af2e68e480b70154156d9c756": "Publish Advisories\n\nGHSA-7pr5-w74r-jjj7\nGHSA-2r2c-cx56-8933\nGHSA-3h6h-67x3-cv5x\nGHSA-3wrr-7qpf-2prh\nGHSA-47qp-hqvx-6r3f\nGHSA-4w6r-5c2j-qf5f\nGHSA-52fw-7fw2-fmv5\nGHSA-5hh8-q8hv-fr38\nGHSA-6mhr-74x2-98v9\nGHSA-9fxm-vc8v-hj55\nGHSA-g72g-r7m4-9x4g\nGHSA-gprh-27j3-g5h4\nGHSA-h6vv-pcq8-7xm4\nGHSA-hgj6-7826-r7m5\nGHSA-hmcr-rmjq-47qr\nGHSA-j3rv-43j4-c7qm\nGHSA-r989-7g3j-wjhw\nGHSA-rcqc-6cw3-h962\nGHSA-rmj7-2vxq-3g9f\nGHSA-g796-fgmg-93mv",
42+
"3fdade359a569c7904e212331250ace917aff918": "Publish Advisories\n\nGHSA-2c85-rfcc-g74j\nGHSA-2r2c-cx56-8933\nGHSA-2vcc-5v34-9jc8\nGHSA-47qp-hqvx-6r3f\nGHSA-64mm-vxmg-q3vj\nGHSA-6x8v-2fq5-2229\nGHSA-94jp-7776-qj6q\nGHSA-gcq2-9pq2-cxqm"
43+
},
44+
"GHSA-HCJR-322H-429R": {
45+
"9f2122f00517f397a625bcc061bd2d2e0983b8e4": "Improve GHSA-hcjr-322h-429r",
46+
"49899a53e9c2e620c99e0234afe3c50e512ad851": "Publish Advisories\n\nGHSA-29gr-w86r-vj34\nGHSA-33r9-fx8q-w69h\nGHSA-4w7g-2ph6-pm6g\nGHSA-5827-wp8x-c8xh\nGHSA-5hp5-q35j-vjpg\nGHSA-c269-4hpf-qfhc\nGHSA-ccmw-x5fc-v2mm\nGHSA-cwxf-7cw2-7r32\nGHSA-f943-xhh7-7c5g\nGHSA-fqc6-vqq8-5xwp\nGHSA-hcjr-322h-429r\nGHSA-j33g-47h2-2687\nGHSA-vjx2-fp9g-q2mc\nGHSA-w35c-8999-xv6m"
47+
},
448
"GHSA-C9CV-MQ2M-PPP3": {
549
"bfd6f934eef6dec09fbcb515b31f7dbf48b7150b": "Improve GHSA-c9cv-mq2m-ppp3",
650
"fe5203d788862f1fed8424a28c9550d7a8b80d5f": "Publish Advisories\n\nGHSA-mqpr-49jj-32rc\nGHSA-3875-8gcx-7v46\nGHSA-c9cv-mq2m-ppp3",
@@ -798,14 +842,6 @@
798842
"GHSA-VV6V-98GX-R829": {
799843
"15947508561deecef44ca4c98dfe3e808a27a7b3": "Publish Advisories\n\nGHSA-cfxc-ch9m-pr95\nGHSA-47xc-xmwq-4cxw\nGHSA-4p7v-v4v3-f9cp\nGHSA-4xg3-6338-9rxr\nGHSA-786x-w3wg-jwf8\nGHSA-8933-qpw2-wm45\nGHSA-9r9x-mp6x-7vh3\nGHSA-fjfr-wjrh-qmv2\nGHSA-fv9j-hvjm-h9xh\nGHSA-ghxv-gf56-x785\nGHSA-hcmx-6x6r-f6mp\nGHSA-m2cx-9w9f-2hm7\nGHSA-pwj4-mv8c-c4xg\nGHSA-vv6v-98gx-r829"
800844
},
801-
"GHSA-QWWW-VCR4-C8H2": {
802-
"76c676188ecfde3b1711d69cf6348b93d71e1d2c": "Improve GHSA-qwww-vcr4-c8h2",
803-
"2de80c26b06c5824ac16f1d5af183e56e486e236": "Improve GHSA-qwww-vcr4-c8h2",
804-
"cd4ee71ce402a4cc78c69988fda1f117c1b64279": "Improve GHSA-qwww-vcr4-c8h2",
805-
"5d6e1e252e6125527d2d29377e6a5c9954dc252f": "Improve GHSA-qwww-vcr4-c8h2",
806-
"4da50480fc88ef6733f73e6cd547ac92f613a0e5": "Improve GHSA-qwww-vcr4-c8h2",
807-
"02ed867ff3261d2dfdd27361617c9d5be6cc80f0": "Publish Advisories\n\nGHSA-464c-974j-9xm6\nGHSA-5xvq-cp9x-6p6r\nGHSA-83w8-p2f5-377r\nGHSA-8pvw-jcv7-9cmj\nGHSA-qwww-vcr4-c8h2\nGHSA-r9mr-m37c-5fr3"
808-
},
809845
"GHSA-PFC9-2CQG-9WQ6": {
810846
"fc3887586f7afd9fa17dd05177145b0694e76f39": "Publish Advisories\n\nGHSA-pfc9-2cqg-9wq6\nGHSA-pfc9-2cqg-9wq6"
811847
},
@@ -2130,16 +2166,6 @@
21302166
"8442743f2a7b08cec213b22005ee7104b0b01251": "Publish Advisories\n\nGHSA-2r5m-76wx-56gx\nGHSA-v853-w46p-fv2h\nGHSA-x5wm-j6wh-2834\nGHSA-35f3-pg38-486f\nGHSA-8f2v-2qhj-gfwg\nGHSA-qg78-vmvc-fhjw\nGHSA-r5xw-gcgw-hwp5\nGHSA-xc7j-3g8q-9vh4\nGHSA-v853-w46p-fv2h",
21312167
"6133595d534771a3e7205104e050d03fd3b325a3": "Publish Advisories\n\nGHSA-m4w8-93pm-87f6\nGHSA-2r5m-76wx-56gx\nGHSA-4c39-fwgj-4vq7\nGHSA-4j5r-6h7v-59cc\nGHSA-6hcw-qqr8-pjj8\nGHSA-89cj-xrpx-j79m\nGHSA-8wv4-h2m6-qrm3\nGHSA-95v7-h9j5-gvjr\nGHSA-9pjg-jh77-2mjg\nGHSA-cvf2-cgfw-jqr4\nGHSA-g9gc-69gg-376j\nGHSA-gprj-xvq8-w53q\nGHSA-hpq4-4cqf-mcg8\nGHSA-m272-v6vr-r4ff\nGHSA-m84h-9wm2-4ch9\nGHSA-mw4m-qhpg-j82m\nGHSA-mxq5-f9c5-w4p5\nGHSA-qhr7-h655-pw6r\nGHSA-vqc2-c9jh-3jjv\nGHSA-w59q-8pf5-r5pc\nGHSA-x2x7-p37c-43cr"
21322168
},
2133-
"GHSA-2R2C-CX56-8933": {
2134-
"ffcf09d2985f26ec684f757049278a4b9426a47f": "Improve GHSA-2r2c-cx56-8933",
2135-
"a98ecc0a2017806af2e68e480b70154156d9c756": "Publish Advisories\n\nGHSA-7pr5-w74r-jjj7\nGHSA-2r2c-cx56-8933\nGHSA-3h6h-67x3-cv5x\nGHSA-3wrr-7qpf-2prh\nGHSA-47qp-hqvx-6r3f\nGHSA-4w6r-5c2j-qf5f\nGHSA-52fw-7fw2-fmv5\nGHSA-5hh8-q8hv-fr38\nGHSA-6mhr-74x2-98v9\nGHSA-9fxm-vc8v-hj55\nGHSA-g72g-r7m4-9x4g\nGHSA-gprh-27j3-g5h4\nGHSA-h6vv-pcq8-7xm4\nGHSA-hgj6-7826-r7m5\nGHSA-hmcr-rmjq-47qr\nGHSA-j3rv-43j4-c7qm\nGHSA-r989-7g3j-wjhw\nGHSA-rcqc-6cw3-h962\nGHSA-rmj7-2vxq-3g9f\nGHSA-g796-fgmg-93mv",
2136-
"3fdade359a569c7904e212331250ace917aff918": "Publish Advisories\n\nGHSA-2c85-rfcc-g74j\nGHSA-2r2c-cx56-8933\nGHSA-2vcc-5v34-9jc8\nGHSA-47qp-hqvx-6r3f\nGHSA-64mm-vxmg-q3vj\nGHSA-6x8v-2fq5-2229\nGHSA-94jp-7776-qj6q\nGHSA-gcq2-9pq2-cxqm"
2137-
},
2138-
"GHSA-47QP-HQVX-6R3F": {
2139-
"8e006d478bda57c4db78c71461a9fa0bba93e500": "Improve GHSA-47qp-hqvx-6r3f",
2140-
"a98ecc0a2017806af2e68e480b70154156d9c756": "Publish Advisories\n\nGHSA-7pr5-w74r-jjj7\nGHSA-2r2c-cx56-8933\nGHSA-3h6h-67x3-cv5x\nGHSA-3wrr-7qpf-2prh\nGHSA-47qp-hqvx-6r3f\nGHSA-4w6r-5c2j-qf5f\nGHSA-52fw-7fw2-fmv5\nGHSA-5hh8-q8hv-fr38\nGHSA-6mhr-74x2-98v9\nGHSA-9fxm-vc8v-hj55\nGHSA-g72g-r7m4-9x4g\nGHSA-gprh-27j3-g5h4\nGHSA-h6vv-pcq8-7xm4\nGHSA-hgj6-7826-r7m5\nGHSA-hmcr-rmjq-47qr\nGHSA-j3rv-43j4-c7qm\nGHSA-r989-7g3j-wjhw\nGHSA-rcqc-6cw3-h962\nGHSA-rmj7-2vxq-3g9f\nGHSA-g796-fgmg-93mv",
2141-
"3fdade359a569c7904e212331250ace917aff918": "Publish Advisories\n\nGHSA-2c85-rfcc-g74j\nGHSA-2r2c-cx56-8933\nGHSA-2vcc-5v34-9jc8\nGHSA-47qp-hqvx-6r3f\nGHSA-64mm-vxmg-q3vj\nGHSA-6x8v-2fq5-2229\nGHSA-94jp-7776-qj6q\nGHSA-gcq2-9pq2-cxqm"
2142-
},
21432169
"GHSA-6R62-QF74-XPGG": {
21442170
"734adcc0a68fbe95325e836d2469be64740b89d7": "Publish Advisories\n\nGHSA-6r62-qf74-xpgg\nGHSA-39xj-89xc-9j56\nGHSA-4vf6-f9c7-q6rp\nGHSA-5qxf-w5v2-m3rg\nGHSA-7r4g-5584-3hjx\nGHSA-ccv6-5mc2-jm5q\nGHSA-cg9r-cc95-vm62\nGHSA-f55h-4j35-8285\nGHSA-gmmh-575h-g7v8\nGHSA-jjqh-m423-q994\nGHSA-jp43-qmg3-xrhw\nGHSA-mffw-2crm-m32h\nGHSA-vrqp-vqfm-w2jv\nGHSA-wj9f-vqw7-855c\nGHSA-xr23-vhrq-p5fv"
21452171
},
@@ -6276,9 +6302,6 @@
62766302
"GHSA-FQC6-VQQ8-5XWP": {
62776303
"49899a53e9c2e620c99e0234afe3c50e512ad851": "Publish Advisories\n\nGHSA-29gr-w86r-vj34\nGHSA-33r9-fx8q-w69h\nGHSA-4w7g-2ph6-pm6g\nGHSA-5827-wp8x-c8xh\nGHSA-5hp5-q35j-vjpg\nGHSA-c269-4hpf-qfhc\nGHSA-ccmw-x5fc-v2mm\nGHSA-cwxf-7cw2-7r32\nGHSA-f943-xhh7-7c5g\nGHSA-fqc6-vqq8-5xwp\nGHSA-hcjr-322h-429r\nGHSA-j33g-47h2-2687\nGHSA-vjx2-fp9g-q2mc\nGHSA-w35c-8999-xv6m"
62786304
},
6279-
"GHSA-HCJR-322H-429R": {
6280-
"49899a53e9c2e620c99e0234afe3c50e512ad851": "Publish Advisories\n\nGHSA-29gr-w86r-vj34\nGHSA-33r9-fx8q-w69h\nGHSA-4w7g-2ph6-pm6g\nGHSA-5827-wp8x-c8xh\nGHSA-5hp5-q35j-vjpg\nGHSA-c269-4hpf-qfhc\nGHSA-ccmw-x5fc-v2mm\nGHSA-cwxf-7cw2-7r32\nGHSA-f943-xhh7-7c5g\nGHSA-fqc6-vqq8-5xwp\nGHSA-hcjr-322h-429r\nGHSA-j33g-47h2-2687\nGHSA-vjx2-fp9g-q2mc\nGHSA-w35c-8999-xv6m"
6281-
},
62826305
"GHSA-J33G-47H2-2687": {
62836306
"49899a53e9c2e620c99e0234afe3c50e512ad851": "Publish Advisories\n\nGHSA-29gr-w86r-vj34\nGHSA-33r9-fx8q-w69h\nGHSA-4w7g-2ph6-pm6g\nGHSA-5827-wp8x-c8xh\nGHSA-5hp5-q35j-vjpg\nGHSA-c269-4hpf-qfhc\nGHSA-ccmw-x5fc-v2mm\nGHSA-cwxf-7cw2-7r32\nGHSA-f943-xhh7-7c5g\nGHSA-fqc6-vqq8-5xwp\nGHSA-hcjr-322h-429r\nGHSA-j33g-47h2-2687\nGHSA-vjx2-fp9g-q2mc\nGHSA-w35c-8999-xv6m"
62846307
},

data/fix-commits/angular-cli-4a405ed0.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://github.com/angular/angular-cli",
33
"vulnerabilities": {
4+
"GHSA-FXQJ-RQCC-2CMP": {
5+
"972f6db7e9ccf3c4b0e895341a49b104a8b0ac9b": "fix(@angular-devkit/build-angular): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp\n\nTAG=agy\n\nCONV=63a146aa-f34e-4200-88d1-90537150adb0",
6+
"8de75ada503d4182af7f0be957e58fe678a63b98": "fix(@angular/build): upgrade postcss to 8.5.23\n\nThis addresses https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp\n\nTAG=agy\n\nCONV=63a146aa-f34e-4200-88d1-90537150adb0"
7+
},
48
"CVE-2026-55603": {
59
"df54298712bb84ec079787e4ca6c0164f6358cf1": "fix(@angular-devkit/build-angular): update http-proxy-middleware to 3.0.7\n\nThis updates http-proxy-middleware to version 3.0.7 to address a security vulnerability.\n\nCVE-2026-55603.\n\nFixes #33534",
610
"d4e07cb3e3f871822f9bf37fdea35814ec1cdb80": "fix(@angular-devkit/build-angular): update http-proxy-middleware to 3.0.7\n\nThis updates http-proxy-middleware to version 3.0.7 to address a security vulnerability.\n\nCVE-2026-55603.\n\nFixes #33534"

data/fix-commits/hadoop-986f98da.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,11 @@
11
{
22
"vcs_url": "https://github.com/apache/hadoop",
33
"vulnerabilities": {
4+
"CVE-2026-59949": {
5+
"6dd24f5815f25431e6eab58e7f16894d1446b708": "HADOOP-19949. Upgrade lz4-java to 1.11.1 due to CVE-2026-59949 (#8643)\n\nAuthored-by: PJ Fanning <fanningpj@apache.org>\nReviewed-by: Shilun Fan <slfan1989@apache.org>\nSigned-off-by: Cheng Pan <chengpan@apache.org>",
6+
"d80ff0aaf4660280ebd628a4cad93e09f9250764": "HADOOP-19949. Upgrade lz4-java to 1.11.1 due to CVE-2026-59949 (#8643)\n\nAuthored-by: PJ Fanning <fanningpj@apache.org>\nReviewed-by: Shilun Fan <slfan1989@apache.org>\nSigned-off-by: Cheng Pan <chengpan@apache.org>",
7+
"cd988431dcb54985ecf15c2c55e450a58bfe37e1": "HADOOP-19949. Upgrade lz4-java to 1.11.1 due to CVE-2026-59949 (#8643)\n\nAuthored-by: PJ Fanning <fanningpj@apache.org>\nReviewed-by: Shilun Fan <slfan1989@apache.org>\nSigned-off-by: Cheng Pan <chengpan@apache.org>"
8+
},
49
"CVE-2026-45205": {
510
"c0649706c341f117fd440e7e9c629034eb010bd2": "HADOOP-19945. Update to commons-configuration2 2.15.0, commons-lang3 3.20.0 and commons-io 2.22.0 to fix CVE-2026-45205 (#8634)\n\nReviewed-by: Shilun Fan <slfan1989@apache.org>\nReviewed-by: Ayush Saxena <ayushsaxena@apache.org>\nSigned-off-by: Cheng Pan <chengpan@apache.org>",
611
"e91e948d5b0aeb424b06016df351c50cdad18d54": "HADOOP-19945. Update to commons-configuration2 2.15.0, commons-lang3 3.20.0 and commons-io 2.22.0 to fix CVE-2026-45205 (#8634)\n\nReviewed-by: Shilun Fan <slfan1989@apache.org>\nReviewed-by: Ayush Saxena <ayushsaxena@apache.org>\nSigned-off-by: Cheng Pan <chengpan@apache.org>"

data/fix-commits/opa-8ab59e31.json

Lines changed: 4 additions & 0 deletions
Large diffs are not rendered by default.

data/fix-commits/php-src-b629c133.json

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,17 @@
11
{
22
"vcs_url": "https://github.com/php/php-src",
33
"vulnerabilities": {
4+
"GHSA-7QPV-R5MR-78M4": {
5+
"3fc97b66066db27f20d846b8ba8560830d6aee3e": "Merge branch 'PHP-8.5'\n\n* PHP-8.5:\n [skip ci] Remove CLEAN from GHSA-7qpv-r5mr-78m4.phpt in PHP 8.2",
6+
"8ec60b1ec15244e857a5a0fbf614c96b76024c34": "Merge branch 'PHP-8.4' into PHP-8.5\n\n* PHP-8.4:\n [skip ci] Remove CLEAN from GHSA-7qpv-r5mr-78m4.phpt in PHP 8.2",
7+
"99e84f3697f1600c7bf13a4c61aa5abe77388780": "Merge branch 'PHP-8.3' into PHP-8.4\n\n* PHP-8.3:\n [skip ci] Remove CLEAN from GHSA-7qpv-r5mr-78m4.phpt in PHP 8.2",
8+
"4399d646d1b50df9b9bbd51c4900f2b4f46715e0": "Merge branch 'PHP-8.2' into PHP-8.3\n\n* PHP-8.2:\n [skip ci] Remove CLEAN from GHSA-7qpv-r5mr-78m4.phpt in PHP 8.2",
9+
"642f069bd48b1a3bb20e657df210b9e6949ca073": "[skip ci] Remove CLEAN from GHSA-7qpv-r5mr-78m4.phpt in PHP 8.2\n\nThe CLEAN section causes issues in CI on Windows + PHP 8.2 + ext-pgsql. This was\nfixed in 94dc6ae871763af5b5bd9bbf0aab29beb07ab8ac, but landed only in 8.3+.",
10+
"4b4baffc1fca4d559c54e835d91df6cc9a8c945a": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
11+
"99be038cc10a4c310db0c5002a69654d0a768fc3": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
12+
"ab048bd83b578119cf81b456526d50498421d617": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
13+
"53ac7025451c6481d44cf1835bb8385299a6a3a3": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4"
14+
},
415
"CVE-2026-9672": {
516
"fb217524830e9fe5a16419e4954239ec393c3e14": "Merge branch 'PHP-8.5'\n\n* PHP-8.5:\n Fix out-of-bounds write in ext-bcmath bccomp() via bc_str2num()\n Add NEWS entries\n Fix GHSA-vc5h-9ppw-p5f3: phar circular symlink crash\n Fix SQL injection in ext-pgsql via E'...' backslash breakout\n libgd patch for CVE-2026-9672",
617
"e5c3b4b083354d24f7202ccdb82f00a61bb16fe8": "Merge branch 'PHP-8.4' into PHP-8.5\n\n* PHP-8.4:\n Fix out-of-bounds write in ext-bcmath bccomp() via bc_str2num()\n Add NEWS entries\n Fix GHSA-vc5h-9ppw-p5f3: phar circular symlink crash\n Fix SQL injection in ext-pgsql via E'...' backslash breakout\n libgd patch for CVE-2026-9672",
@@ -26,12 +37,6 @@
2637
"ce2ec8a70755dca6da50cf4a5f663696eb5230d0": "Fix out-of-bounds write in ext-bcmath bccomp() via bc_str2num()\n\nWhen a fraction is truncated to a caller-supplied scale and then re-trimmed of\ntrailing zeros, str_scale was reduced but fractional_end was not, so\nbc_copy_and_toggle_bcd() copied more bytes than were reserved by\nbc_new_num_nonzeroed(). With small numbers allocated from the 256-byte stack\narena this is a stack-based OOB write reachable via bccomp($num1, $num2,\n$scale), e.g. bccomp(\"1.901\", \"0\", 2).\n\nKeep fractional_end in sync with str_scale so the copy length matches the\nreserved length.\n\nFixes GHSA-x692-q9x7-8c3f",
2738
"fa18dab73f9340448c0d5c0a1d75d3fec844b358": "Fix out-of-bounds write in ext-bcmath bccomp() via bc_str2num()\n\nWhen a fraction is truncated to a caller-supplied scale and then re-trimmed of\ntrailing zeros, str_scale was reduced but fractional_end was not, so\nbc_copy_and_toggle_bcd() copied more bytes than were reserved by\nbc_new_num_nonzeroed(). With small numbers allocated from the 256-byte stack\narena this is a stack-based OOB write reachable via bccomp($num1, $num2,\n$scale), e.g. bccomp(\"1.901\", \"0\", 2).\n\nKeep fractional_end in sync with str_scale so the copy length matches the\nreserved length.\n\nFixes GHSA-x692-q9x7-8c3f"
2839
},
29-
"GHSA-7QPV-R5MR-78M4": {
30-
"4b4baffc1fca4d559c54e835d91df6cc9a8c945a": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
31-
"99be038cc10a4c310db0c5002a69654d0a768fc3": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
32-
"ab048bd83b578119cf81b456526d50498421d617": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4",
33-
"53ac7025451c6481d44cf1835bb8385299a6a3a3": "Fix SQL injection in ext-pgsql via E'...' backslash breakout\n\nphp_pgsql_add_quotes() quotes the string with E'...', but PQescapeStringConn()\ndoes not escape \\ unless standard_conforming_strings is off.\nPQescapeStringConn() is meant to be used with '', so do that instead.\n\nFixes GHSA-7qpv-r5mr-78m4"
34-
},
3540
"CVE-2026-44927": {
3641
"bb739429b48130b0654fc460d4fee22e721b4cd8": "uri: Update to uriparser-1.0.2 (#22070)\n\nThis fixes CVE-2026-44927 and CVE-2026-44928."
3742
},

0 commit comments

Comments
 (0)