Zend Server 2021.4.8
Back to top
Back to topZS2021.4.8
Included PHP versions: 7.4.33.16, 7.3.33.22, 7.2.34.30, 7.1.33.32
CVE fixes: CVE-2026-91768, CVE-2025-1218, CVE-2026-91769, CVE-2026-91767, CVE-2026-6103, CVE-2026-91765, CVE-2025-14181, CVE-2026-92842, CVE-2026-91766, CVE-2026-93682, CVE-2026-17545
Changes
- Filter
- Fixed GHSA-ch8v-r6jh-4vvr (
FILTER_SANITIZE_ENCODEDdoes not encode 0xFF). (Ilia Alshanetsky)
- Fixed GHSA-ch8v-r6jh-4vvr (
- FPM
- Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI
listen.allowed_clientsdue to partial address comparison). (CVE-2026-91768) (Alexandre Daubois)
- Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI
- MySQLnd
- Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) (Jakub Zelenka, Nora Dossche)
- OpenSSL
- Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) (Jakub Zelenka)
- Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in
php_openssl_matches_wildcard_name()on crafted server certificate wildcard CN). (CVE-2026-91767) (Jakub Zelenka)
- Phar
- Fixed GHSA-j3wh-g957-2m85 (Integer overflow in
phar_tar_number()allowing TAR archive entry injection). (CVE-2026-6103) (Jakub Zelenka)
- Fixed GHSA-j3wh-g957-2m85 (Integer overflow in
- SOAP
- Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side
cleanup_xml_node()). (CVE-2026-91765) (Alexandre Daubois) - Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) (Nora Dossche, Jakub Zelenka)
- Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side
- Standard
- Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in
convert.*stream filters when line-break-chars contains NUL). (CVE-2026-92842) (geeknik) - Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) (Alexandre Daubois, Jakub Zelenka)
- Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) (Ilia Alshanetsky, Jordi Kroon)
- Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in
- Windows
- Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545) (Shivam Mathur, Jakub Zelenka)