PHP shipped a significant round of updates with versions 8.5.11, 8.4.26, 8.3.35, and 8.2.34, along with a release candidate for PHP 8.6. All four stable releases address security vulnerabilities in FPM, OpenSSL, Phar, and HTTP redirect handling.
Key fixes include a bypass of the FastCGI allowed-clients list and a credential leak when requests are redirected to another domain. Production users should review the changelog and plan upgrades accordingly. Versions 8.3 and 8.2 are now in security-fix-only mode, receiving no feature updates.
PHP 8.6 is in testing phase with notable features like partial function application, enabling you to fill some function arguments and return a new callable, plus a clamp() function that constrains values to a range. The release also includes changes to readonly properties and new APIs for time duration and I/O operations. A packaging error in the initial RC1 announcement led to the first official release candidate being labeled RC2. Developers are encouraged to test their applications and report issues on GitHub. RC3 is scheduled for October 8.