Updates for version 2018.0.3

Updates for version 2018.0.2

  • Windows only

  • Update Apache to version: 2.4.37 (OpenSSL 1.1.1a)

Updates for version 2018.0.1

  • PHP 7.2.10 - http://www.php.net/ChangeLog-7.php#7.2.10

  • Updates since 2018.0.0
    • CVEs
      • EXIF: Fixed bug #76409 (heap use after free in _php_stream_free). (CVE-2018-12882)
      • EXIF: Fixed bug #76423 (Int Overflow lead to Heap OverFlow in exif_thumbnail_extract of exif.c). (CVE-2018-14883)
      • EXIF: Fixed bug #76557 (heap-buffer-overflow (READ of size 48) while reading exif data). (CVE-2018-14851)
      • Win32: Fixed bug #76459 (windows linkinfo lacks openbasedir check). (CVE-2018-15132)
    • Zend Server fixes
      • Cannot define application with manually typed base URL (ZSR-3080)
      • Cannot define application on a non default VHost(ZSR-3081)
      • Zend Server fails to install on Ubuntu 18.04 due to new SSL files dependency failure (ZSR-2573)
      • Monitoring rules: functions list is not populated (ZSR-2952)

Introducing Zend Server 2018

Read all about our Zend Server 2018 features and capabilities in the What’s New page.

PHP & Extensions

  • PHP 7.2.6
  • Memcached extension - included only for Linux and Mac
  • Bundled MySQL 5.7 for Windows installations


For detailed installation instructions for all supported operating systems, please refer to the Zend Server 2018 Installation Guide


  • Upgrades from Zend Server 9.0.X are supported. Upgrades from older versions are not supported

  • When upgrading PHP from PHP 7.0.X to PHP 7.2, configuration settings (php.ini) are not retained and a the new php.ini is used
  • Linux
    • Upgrade from earlier version with a different PHP on DEB may fail on due to: php-7.x-java-bridge-zend-server unmet dependencies. Workaround: remove java-bridge, then upgrade (ZSRV-10436)

Limitations and Known Issues

The following issues are known at the time of the Zend Server 9.1 release:

  • Deployment:
    • If a ZPK contains non-valid monitoring rules, the deployment fails (change of behavior)
    • Nginx: deploying to the root of the default virtual host does not work out-of-the-box and causes configuration problems (ZSRV-10098). Workaround: comment out the location / entry in /etc/nginx/conf.d/default.conf
      #location / {
      # include /etc/nginx/fastcgi.conf;
      # root /usr/share/nginx/html;
      # index index.php index.html index.htm;
      # }
  • RPM + FPM/NGINX - alert messages in php-fpm.log ("unknown child"). Can be ignored
  • Job Queue:
    • CLI - running a batch command required the .bat suffix
    • Enforcement of recurring jobs names: the job name must be unique
  • The directive zend_monitor.event_generate_trace_file is replaced by zend_monitor.event_tracing_mode
  • Page Cache will not store or fetch cached pages when Z-Ray is enabled. This is true also in Z-Ray Selective mode.
  • WebAPI 'applicationGetStatus' - 'baseUrl' parameter - < default-server > is replaced by the server IP
  • Secured VHost
    • Vhosts validation is skipped where exists a secured Vhost
    • SSL Certificates are not validated when editing or creating secured vhosts. The user must verify that certificate paths and content are valid, before applying in a secured vhost
  • Data Cache
    • Enhanced API - fetch function can now get a callable function as a parameter
      • zend_shm_cache_fetch (key, callable)
      • zend_disk_cache_fetch(key, callable)
        In case of cache miss, the user callable code will be triggered and the returned value will be stored automatically for the specified key, instead of using an extra cache_store API call
    • zend_datacache.shm.memory_cache_size_kb is removed. To limit the shm memory size use zend_datacache.shm.memory_cache_size. Its value is in Mb
    • API function zend_shm_cache_info() return value is in Bytes
    • Added a new directive: "default_ttl" for setting default Time to Live (TTL) value per cache entry
    • APC compatibility was deprecated in Zend Server 9.1. In this version we removed it altogether. Directive zend_datacache.apc_compatibility is removed
  • Z-Ray
    • Z-Ray might be blocked by using the browser content security policy (e.g. PHPMyADmin on Firefox)
    • When using Z-Ray with Load Balanced domains, a special setup is needed:
      • An accessible ZS GUI address must be set in Z-Ray settings ( Zend Server Menu -> Z-Ray -> Settings -> Advanced)
      • The Load Balancer IP address must be included in the Z-Ray allowed IPs list (token)
    • Z-Ray is not to be included or enabled in performance tests context (e.g. in AB testing)
    • Z-Ray currently supports the following database drivers: PDO, MySQL/i, OCI8 , sqlite3 and DB2
  • Mac
    • Upgrades for Mac from 9.0.x to a later version are not supported (due to Apache changes)
    • sending email using TLS requires the following manual configuration:
    • Get latest cert files:
      curl -k https://curl.haxx.se/ca/cacert.pem > /System/Library/OpenSSL/certs/cacert.pem
    • add the following to /usr/local/zend/gui/lighttpd/etc/php-fcgi.ini :

IBMi specific release notes


  • Zend Server for IBM i 2018 can be installed as a new installation on a partition running Zend Server for IBM i 8.x, and both can be run at the same time, allowing for a migration from version 8 to version 2018.


  • Zend Server for IBMi now supports cluster! It requires the new Zend DBi (MariaDB)