PHP 8.2–8.5 Security Releases Fix 11 CVEs Across Drupal-Compatible Runtimes
Four maintained PHP branches used across current Drupal deployments received security releases on 24 September 2026 that fix 11 named CVEs and an additional Filter issue. PHP released versions 8.2.34, 8.3.35, 8.4.26 and 8.5.11 and advises users of each branch to upgrade.
The fixes cover HTTP redirect handling, TLS hostname verification, PHP-FPM access controls, MySQL Native Driver processing, Phar archives, SOAP, stream filters and Windows filesystem behaviour. Their Drupal relevance comes from the underlying PHP runtime rather than a vulnerability in Drupal core, and exposure depends on the PHP components, configuration and application behaviour present on an individual system.
Drupal's currently security-supported production lines span several of the patched branches. Among the versions covered by the September releases, Drupal 10.6 supports PHP 8.2 through 8.4, while Drupal 11.3 and 11.4 support PHP 8.3 through 8.5. Drupal 12 requires PHP 8.5, although the 12.0.0 line remains pre-release and is not intended for production use.
One fix, CVE-2026-91766, concerns PHP's HTTP stream handling when requests follow redirects. Under affected conditions, user-supplied headers such as Authorization, Cookie or Proxy-Authorization could be forwarded to another origin. A Drupal installation is relevant to this issue only where application code uses the affected PHP stream behaviour with credentials that can be carried into a redirected request.
PHP-FPM deployments have a separate exposure condition. One of the fixes addresses an IPv6 bypass involving listen.allowed_clients, a setting used to restrict FastCGI clients. Its significance therefore depends on whether an environment uses PHP-FPM with that access-control mechanism and how the FPM service is exposed.
Other fixes address malformed packets handled by mysqlnd, crafted Phar TAR entries, SOAP parsing and recursion problems, stream-filter out-of-bounds reads and Windows reserved-device-name handling. Those conditions do not apply uniformly to every Drupal installation. Extensions, operating systems, SAPIs and application code determine which parts of the security batch are relevant to a particular environment.
Managed platforms have already begun incorporating the patched releases. Pantheon reported on 25 September that PHP 8.2.34, 8.3.35, 8.4.26 and 8.5.11 were available on its platform and said the updates would be applied automatically over the following days. Its release note highlighted fixes affecting SOAP, OpenSSL certificate verification, HTTP streams and PHP-FPM.
Acquia customers using PHP 8.2 face an additional lifecycle change. Acquia supports PHP 8.2 through 8.5 but plans to remove PHP 8.2 on 1 October 2026 and move remaining environments on that branch to PHP 8.4. Affected customers may therefore encounter a PHP branch upgrade alongside the immediate security-update cycle.
Containerised Drupal installations require operators to confirm that patched runtime images have actually reached deployed workloads. Availability of an updated base image does not replace already running containers, so application images may need to be rebuilt and redeployed. Web containers, queue workers, cron processes and other long-running PHP workloads should be checked separately where infrastructure uses distinct images or runtime configurations.
Distribution packages require similar care because package revisions do not always mirror upstream PHP version strings. Debian published DSA-6514-1 on 25 September with PHP 8.4 security fixes for Debian 13, including the package version 8.4.26-1~deb13u1. Operators using distribution or hosting-provider packages should therefore consult the relevant vendor advisory rather than classify patch status from an upstream version number alone.
Command-line PHP can also differ from the process serving Drupal through a web server or PHP-FPM. Checking php -v over SSH may confirm the CLI runtime without establishing what Drupal itself, Drush, cron, queue workers or separate containers are executing. Each relevant runtime needs to be checked against the applicable vendor or upstream fix.
Drupal 10.6 also permits PHP 8.1, creating a separate lifecycle issue outside this security batch. Upstream support for PHP 8.1 ended on 31 December 2025, and the branch did not receive a corresponding September 2026 security release. Drupal compatibility therefore does not mean that every permitted PHP branch still receives upstream security maintenance.
Operators using PHP 8.2 through 8.5 should identify the runtime serving each workload and confirm whether the corresponding patched upstream release, distribution package, managed-hosting update or rebuilt container is deployed. PHP lists the individual fixes in its PHP 8 changelog, while Drupal documents version compatibility in its PHP requirements guide.
References
-
PHP 8.2.34 Release Announcement (24 September 2026)
-
PHP 8.3.35 Release Announcement (24 September 2026)
-
PHP 8.4.26 Release Announcement (24 September 2026)
-
PHP 8.5.11 Release Announcement (24 September 2026)
-
drupal 11.4.7 | Drupal.org (16 September 2026)
-
Cross-Origin Credential Leak in HTTP Stream Wrapper Redirects (24 September 2026)
-
PHP 8.2, 8.3, 8.4 and 8.5 Updated to Their Latest Security Patch Releases, Pantheon (25 September 2026)
