PHP 8.x — End of Life
Active Critical risk EOL: Dec 31, 2029in 1210d6 releases in this series72 CVEs
PHP 8.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 8.5 | Nov 20, 2025 | Dec 31, 2027 | Dec 31, 2029 | 8.5.10 | Active | |
| 8.4 | Nov 21, 2024 | Dec 31, 2026 | Dec 31, 2028 | 8.4.25 | Active | |
| 8.3 | Nov 23, 2023 | Dec 31, 2025 | Dec 31, 2027 | 8.3.33 | Active | |
| 8.2 | Dec 8, 2022 | Dec 31, 2024 | Dec 31, 2026 | 8.2.33 | Active | |
| 8.1 | Nov 25, 2021 | Nov 25, 2023 | Dec 31, 2025 | 8.1.34 | EOL | |
| 8.0 | Nov 26, 2020 | Nov 26, 2022 | Nov 26, 2023 | 8.0.30 | EOL |
CVEs affecting PHP 8.x (72)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-7260 | MEDIUM | 5.5 | 0.11% | — | 8.2 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP … | Jul 30, 2026 |
| CVE-2026-7260 | MEDIUM | 5.5 | 0.11% | — | 8.5 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP … | Jul 30, 2026 |
| CVE-2026-7260 | MEDIUM | 5.5 | 0.11% | — | 8.3 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP … | Jul 30, 2026 |
| CVE-2026-7260 | MEDIUM | 5.5 | 0.11% | — | 8.4 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP … | Jul 30, 2026 |
| CVE-2026-17544 | CRITICAL | 9.8 | 0.42% | — | 8.5 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions… | Jul 30, 2026 |
| CVE-2026-17544 | CRITICAL | 9.8 | 0.42% | — | 8.4 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions… | Jul 30, 2026 |
| CVE-2026-17543 | CRITICAL | 9.8 | 0.32% | — | 8.5 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f… | Jul 30, 2026 |
| CVE-2026-17543 | CRITICAL | 9.8 | 0.32% | — | 8.4 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f… | Jul 30, 2026 |
| CVE-2026-17543 | CRITICAL | 9.8 | 0.32% | — | 8.2 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f… | Jul 30, 2026 |
| CVE-2026-17543 | CRITICAL | 9.8 | 0.32% | — | 8.3 | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f… | Jul 30, 2026 |
| CVE-2026-14355 | MEDIUM | 5.6 | 0.27% | — | 8.5 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo… | Jul 3, 2026 |
| CVE-2026-14355 | MEDIUM | 5.6 | 0.27% | — | 8.2 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo… | Jul 3, 2026 |
| CVE-2026-14355 | MEDIUM | 5.6 | 0.27% | — | 8.4 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo… | Jul 3, 2026 |
| CVE-2026-14355 | MEDIUM | 5.6 | 0.27% | — | 8.3 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo… | Jul 3, 2026 |
| CVE-2026-7263 | HIGH | 7.5 | 0.35% | — | 8.5 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly,… | May 10, 2026 |
| CVE-2026-7263 | HIGH | 7.5 | 0.35% | — | 8.4 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly,… | May 10, 2026 |
| CVE-2026-6104 | CRITICAL | 9.1 | 0.46% | — | 8.5 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is pas… | May 10, 2026 |
| CVE-2026-6104 | CRITICAL | 9.1 | 0.46% | — | 8.4 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is pas… | May 10, 2026 |
| CVE-2026-7568 | HIGH | 7.5 | 0.45% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f… | May 10, 2026 |
| CVE-2026-7568 | HIGH | 7.5 | 0.45% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f… | May 10, 2026 |
| CVE-2026-7568 | HIGH | 7.5 | 0.45% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f… | May 10, 2026 |
| CVE-2026-7568 | HIGH | 7.5 | 0.45% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f… | May 10, 2026 |
| CVE-2026-7262 | HIGH | 7.5 | 0.78% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve… | May 10, 2026 |
| CVE-2026-7262 | HIGH | 7.5 | 0.78% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve… | May 10, 2026 |
| CVE-2026-7262 | HIGH | 7.5 | 0.78% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve… | May 10, 2026 |
| CVE-2026-7262 | HIGH | 7.5 | 0.78% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve… | May 10, 2026 |
| CVE-2026-7261 | CRITICAL | 9.8 | 0.30% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i… | May 10, 2026 |
| CVE-2026-7261 | CRITICAL | 9.8 | 0.30% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i… | May 10, 2026 |
| CVE-2026-7261 | CRITICAL | 9.8 | 0.30% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i… | May 10, 2026 |
| CVE-2026-7261 | CRITICAL | 9.8 | 0.30% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i… | May 10, 2026 |
| CVE-2026-7259 | MEDIUM | 6.5 | 0.20% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch betwee… | May 10, 2026 |
| CVE-2026-7259 | MEDIUM | 6.5 | 0.20% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch betwee… | May 10, 2026 |
| CVE-2026-7259 | MEDIUM | 6.5 | 0.20% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch betwee… | May 10, 2026 |
| CVE-2026-7259 | MEDIUM | 6.5 | 0.20% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch betwee… | May 10, 2026 |
| CVE-2026-7258 | HIGH | 7.5 | 0.33% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i… | May 10, 2026 |
| CVE-2026-7258 | HIGH | 7.5 | 0.33% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i… | May 10, 2026 |
| CVE-2026-7258 | HIGH | 7.5 | 0.33% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i… | May 10, 2026 |
| CVE-2026-7258 | HIGH | 7.5 | 0.33% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i… | May 10, 2026 |
| CVE-2026-6735 | MEDIUM | 6.1 | 0.21% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanit… | May 10, 2026 |
| CVE-2026-6735 | MEDIUM | 6.1 | 0.21% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanit… | May 10, 2026 |
| CVE-2026-6735 | MEDIUM | 6.1 | 0.21% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanit… | May 10, 2026 |
| CVE-2026-6735 | MEDIUM | 6.1 | 0.21% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanit… | May 10, 2026 |
| CVE-2026-6722 | CRITICAL | 9.8 | 0.89% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio… | May 10, 2026 |
| CVE-2026-6722 | CRITICAL | 9.8 | 0.89% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio… | May 10, 2026 |
| CVE-2026-6722 | CRITICAL | 9.8 | 0.89% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio… | May 10, 2026 |
| CVE-2026-6722 | CRITICAL | 9.8 | 0.89% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio… | May 10, 2026 |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.43% | — | 8.3 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird … | May 10, 2026 |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.43% | — | 8.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird … | May 10, 2026 |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.43% | — | 8.2 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird … | May 10, 2026 |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.43% | — | 8.4 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird … | May 10, 2026 |
| CVE-2025-14180 | HIGH | 7.5 | 0.70% | — | 8.5 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w… | Dec 27, 2025 |
| CVE-2025-14180 | HIGH | 7.5 | 0.70% | — | 8.4 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w… | Dec 27, 2025 |
| CVE-2025-14180 | HIGH | 7.5 | 0.70% | — | 8.2 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w… | Dec 27, 2025 |
| CVE-2025-14180 | HIGH | 7.5 | 0.70% | — | 8.1 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w… | Dec 27, 2025 |
| CVE-2025-14180 | HIGH | 7.5 | 0.70% | — | 8.3 | In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 w… | Dec 27, 2025 |
| CVE-2025-14178 | MEDIUM | 6.5 | 0.46% | — | 8.4 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14178 | MEDIUM | 6.5 | 0.46% | — | 8.3 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14178 | MEDIUM | 6.5 | 0.46% | — | 8.1 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14178 | MEDIUM | 6.5 | 0.46% | — | 8.2 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14178 | MEDIUM | 6.5 | 0.46% | — | 8.5 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14177 | HIGH | 7.5 | 0.51% | — | 8.1 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14177 | HIGH | 7.5 | 0.51% | — | 8.3 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14177 | HIGH | 7.5 | 0.51% | — | 8.2 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14177 | HIGH | 7.5 | 0.51% | — | 8.5 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2025-14177 | HIGH | 7.5 | 0.51% | — | 8.4 | In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, … | Dec 27, 2025 |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.88% | — | 8.1 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d… | Apr 10, 2024 |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.88% | — | 8.3 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d… | Apr 10, 2024 |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.88% | — | 8.2 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d… | Apr 10, 2024 |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.88% | — | 8.0 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d… | Apr 10, 2024 |
| CVE-2023-0567 | HIGH | 7.7 | 0.94% | — | 8.2 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some inval… | Mar 1, 2023 |
| CVE-2023-0567 | HIGH | 7.7 | 0.94% | — | 8.0 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some inval… | Mar 1, 2023 |
| CVE-2023-0567 | HIGH | 7.7 | 0.94% | — | 8.1 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some inval… | Mar 1, 2023 |
Frequently asked questions
Is PHP 8 end of life?
Partially. Some PHP 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect PHP 8?
There are 72 CVEs tracked for PHP 8.x, including 24 critical severity issues. See the full list above with CVSS and EPSS scores.
What is the latest PHP 8 version?
The latest PHP 8.x patch release is 8.5.10, released on August 27, 2026. Always run the latest patch to benefit from all security fixes.
When was PHP 8 first released?
PHP 8.0 was initially released on November 20, 2025. See the full version timeline in the table above.
Is it safe to run PHP 8 in production?
PHP 8 is still supported and safe for production use until December 31, 2029. Ensure you are running the latest patch version (8.5.10) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
