Remi's RPM repository - Packages

Blog | Support | Repository | Wizard

php-cli - Command-line interface for PHP

Website:
http://www.php.net/
Licence:
PHP and Zend and BSD and MIT and ASL 1.0 and NCSA and PostgreSQL
Vendor:
Remi's RPM repository <https://rpms.remirepo.net/> #StandWithUkraine #NoAI
Description:
The php-cli package contains the command-line interface
executing PHP scripts, /usr/bin/php, and the CGI interface.

Packages

php-cli-8.1.34-5.module_php.8.1.el9.remi.x86_64 [5.3 MiB] Changelog by Remi Collet (2026-10-01):
- Fix FILTER_SANITIZE_ENCODED does not encode 0xFF
- Fix IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison
  CVE-2026-91768
- Fixed Various packet overreads in mysqlnd wire protocol
  CVE-2025-1218
- Fix TLS hostname verification falls back to CN after SAN mismatch
  CVE-2026-91769
- Fix Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN
  CVE-2026-91767
- Fix Integer overflow in phar_tar_number() allowing TAR archive entry injection
  CVE-2026-6103
- Fix Unbounded recursion in server-side cleanup_xml_node()
  CVE-2026-91765
- Fix Integer overflow to buffer overflow in SOAP HTTP parsing
  CVE-2025-14181
- Fix Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL
  CVE-2026-92842
- Fix Cross-origin credential leak in HTTP stream wrapper redirects
  CVE-2026-91766
- Fix Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
  CVE-2026-93682
php-cli-8.1.34-4.module_php.8.1.el9.remi.x86_64 [5.3 MiB] Changelog by Remi Collet (2026-07-30):
- Fix leak on double DatePeriod::__construct() call
- Fixed SQL injection via E'...' backslash breakout
  CVE-2026-17543
- Fixed GHSA-vc5h-9ppw-p5f3 Crash via recursive symlinks
  CVE-2026-7260