PHP on Linux: which version fixes what
PHP is the only package on this list where the biggest risk is usually not an unpatched CVE. It is running a branch that stopped receiving them.
SecAI tracks 71 distinct CVEs affecting PHP across the 6 distributions below, of which 12 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.
What it is, and why it is on your server
PHP powers WordPress, Magento, Laravel and most of the shared-hosting web. Distributions ship a specific branch per release: Ubuntu 22.04 has 8.1, Ubuntu 24.04 has 8.3, Debian 12 has 8.2, and the source package name is stamped with the branch.
Why its advisories behave the way they do
- End of life is the finding. Each PHP branch gets two years of bug fixes and one more of security fixes. After that there are no advisories, which reads on a scanner as "no known vulnerabilities" and means the opposite.
- Your distribution and php.net disagree about support. Ubuntu 22.04 keeps patching 8.1 past its upstream end of life, because the LTS promise covers it. The same version number is supported on one system and abandoned on another.
- Multiple versions coexist. A server with a panel often has three PHP branches installed at once and different sites pointed at different ones. Patching the default does nothing for a site pinned to an older branch.
Check what you are actually running
The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.
dpkg-query -W -f='${Package} ${Version}\n' php8.3-cli php8.2-cli php8.1-cli 2>/dev/nullrpm -q php-cliRun `php -v` for the default branch, and on a panel host check each site separately: the default is rarely what the sites are using.
Fixed versions, per distribution
Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.
Ubuntu 22.04 LTSsource package: php8.1
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2025-1218 | 2026-09-24 | no fixed version released |
| CVE-2025-14181 | 2026-09-24 | no fixed version released |
| CVE-2026-17545 | 2026-09-24 | no fixed version released |
| CVE-2026-6103 | 2026-09-24 | no fixed version released |
| CVE-2026-91765 | 2026-09-24 | no fixed version released |
| CVE-2026-91766 | 2026-09-24 | no fixed version released |
| CVE-2026-91767 | 2026-09-24 | no fixed version released |
| CVE-2026-91768 | 2026-09-24 | no fixed version released |
| CVE-2026-91769 | 2026-09-24 | no fixed version released |
| CVE-2026-92842 | 2026-09-24 | no fixed version released |
| CVE-2026-93682 | 2026-09-24 | no fixed version released |
| CVE-2026-17543 | 2026-09-10 | 8.1.2-1ubuntu2.26 |
| CVE-2026-17544 | 2026-09-10 | 8.1.2-1ubuntu2.26 |
| CVE-2026-7260 | 2026-09-10 | 8.1.2-1ubuntu2.26 |
| CVE-2026-12184 | 2026-07-20 | 8.1.2-1ubuntu2.25 |
| CVE-2026-14355 | 2026-07-20 | 8.1.2-1ubuntu2.25 |
| CVE-2025-14179 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-6722 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-6735 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-7259 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-7261 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-7262 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2026-7568 | 2026-05-10 | 8.1.2-1ubuntu2.24 |
| CVE-2025-14177 | 2026-01-12 | 8.1.2-1ubuntu2.23 |
| CVE-2025-14178 | 2026-01-12 | 8.1.2-1ubuntu2.23 |
Showing the 25 most recent of 64 that apply to Ubuntu 22.04 LTS, 12 of which have no fixed version released.
Ubuntu 24.04 LTSsource package: php8.3
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2025-1218 | 2026-09-24 | no fixed version released |
| CVE-2025-14181 | 2026-09-24 | no fixed version released |
| CVE-2026-17545 | 2026-09-24 | no fixed version released |
| CVE-2026-6103 | 2026-09-24 | no fixed version released |
| CVE-2026-91765 | 2026-09-24 | no fixed version released |
| CVE-2026-91766 | 2026-09-24 | no fixed version released |
| CVE-2026-91767 | 2026-09-24 | no fixed version released |
| CVE-2026-91768 | 2026-09-24 | no fixed version released |
| CVE-2026-91769 | 2026-09-24 | no fixed version released |
| CVE-2026-92842 | 2026-09-24 | no fixed version released |
| CVE-2026-93682 | 2026-09-24 | no fixed version released |
| CVE-2026-17543 | 2026-09-10 | 8.3.6-0ubuntu0.24.04.11 |
| CVE-2026-17544 | 2026-09-10 | 8.3.6-0ubuntu0.24.04.11 |
| CVE-2026-7260 | 2026-09-10 | 8.3.6-0ubuntu0.24.04.11 |
| CVE-2026-12184 | 2026-07-20 | 8.3.6-0ubuntu0.24.04.10 |
| CVE-2026-14355 | 2026-07-20 | 8.3.6-0ubuntu0.24.04.10 |
| CVE-2025-14179 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-6722 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-6735 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-7258 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-7259 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-7261 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-7262 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2026-7568 | 2026-05-10 | 8.3.6-0ubuntu0.24.04.9 |
| CVE-2025-14177 | 2026-01-12 | 8.3.6-0ubuntu0.24.04.6 |
Showing the 25 most recent of 48 that apply to Ubuntu 24.04 LTS, 11 of which have no fixed version released.
Debian 12 (bookworm)source package: php8.2
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2025-1218 | 2026-09-25 | no fixed version released |
| CVE-2025-14181 | 2026-09-25 | no fixed version released |
| CVE-2026-6103 | 2026-09-25 | no fixed version released |
| CVE-2026-91765 | 2026-09-25 | no fixed version released |
| CVE-2026-91766 | 2026-09-25 | no fixed version released |
| CVE-2026-91767 | 2026-09-25 | no fixed version released |
| CVE-2026-91768 | 2026-09-25 | no fixed version released |
| CVE-2026-91769 | 2026-09-25 | no fixed version released |
| CVE-2026-92842 | 2026-09-25 | no fixed version released |
| CVE-2026-93682 | 2026-09-25 | no fixed version released |
| CVE-2026-9672 | 2026-07-31 | 8.2.33-1~deb12u1 |
| CVE-2026-17543 | 2026-07-30 | 8.2.33-1~deb12u1 |
| CVE-2026-7260 | 2026-07-30 | 8.2.33-1~deb12u1 |
| CVE-2026-14355 | 2026-07-03 | 8.2.32-1~deb12u1 |
| CVE-2025-14179 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-6722 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-6735 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-7258 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-7259 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-7261 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-7262 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2026-7568 | 2026-05-10 | 8.2.31-1~deb12u1 |
| CVE-2025-14177 | 2026-03-02 | 8.2.30-1~deb12u1 |
| CVE-2025-14178 | 2026-03-02 | 8.2.30-1~deb12u1 |
| CVE-2025-14180 | 2026-03-02 | 8.2.30-1~deb12u1 |
Showing the 25 most recent of 53 that apply to Debian 12 (bookworm), 10 of which have no fixed version released.
Debian 13 (trixie)source package: php8.4
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2025-1218 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2025-14181 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-6103 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-91765 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-91766 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-91767 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-91768 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-91769 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-92842 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-93682 | 2026-09-25 | 8.4.26-1~deb13u1 |
| CVE-2026-9672 | 2026-07-31 | 8.4.24-1~deb13u1 |
| CVE-2026-17543 | 2026-07-30 | 8.4.24-1~deb13u1 |
| CVE-2026-17544 | 2026-07-30 | 8.4.24-1~deb13u1 |
| CVE-2026-7260 | 2026-07-30 | 8.4.24-1~deb13u1 |
| CVE-2026-12184 | 2026-07-03 | 8.4.21-1~deb13u1 |
| CVE-2026-14355 | 2026-07-03 | 8.4.23-1~deb13u1 |
| CVE-2025-14179 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-6104 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-6722 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-6735 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-7258 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-7259 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-7261 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-7262 | 2026-05-10 | 8.4.21-1~deb13u1 |
| CVE-2026-7263 | 2026-05-10 | 8.4.21-1~deb13u1 |
Showing the 25 most recent of 38 that apply to Debian 13 (trixie).
Rocky Linux 9source package: php
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-17543 | 2026-09-02 | 0:8.2.33-1.module+el9.8.0+40305+0c876ebe |
| CVE-2026-7260 | 2026-09-02 | 0:8.2.33-1.module+el9.8.0+40305+0c876ebe |
| CVE-2026-14355 | 2026-08-31 | 0:8.0.30-8.el9_8 |
| CVE-2026-6722 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-6735 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-7258 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-7259 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-7261 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-7262 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2026-7568 | 2026-07-29 | 0:8.0.30-6.el9_8 |
| CVE-2025-14177 | 2026-02-24 | 0:8.0.30-5.el9_7 |
| CVE-2025-14178 | 2026-02-24 | 0:8.0.30-5.el9_7 |
| CVE-2025-1220 | 2025-12-19 | 0:8.3.26-1.module+el9.7.0+40049+21bbec6b |
| CVE-2025-1735 | 2025-12-19 | 0:8.3.26-1.module+el9.7.0+40049+21bbec6b |
| CVE-2025-6491 | 2025-12-19 | 0:8.3.26-1.module+el9.7.0+40049+21bbec6b |
| CVE-2025-1217 | 2025-10-04 | 0:8.0.30-3.el9_6 |
| CVE-2025-1219 | 2025-10-04 | 0:8.0.30-3.el9_6 |
| CVE-2025-1734 | 2025-10-04 | 0:8.0.30-3.el9_6 |
| CVE-2025-1736 | 2025-10-04 | 0:8.0.30-3.el9_6 |
| CVE-2025-1861 | 2025-10-04 | 0:8.0.30-3.el9_6 |
| CVE-2024-11233 | 2025-07-29 | 0:8.1.32-1.module+el9.6.0+32040+1f1dedb8 |
| CVE-2024-11234 | 2025-07-29 | 0:8.1.32-1.module+el9.6.0+32040+1f1dedb8 |
| CVE-2024-8929 | 2025-07-29 | 0:8.1.32-1.module+el9.6.0+32040+1f1dedb8 |
| CVE-2023-0567 | 2023-10-24 | 0:8.0.30-1.el9_2 |
| CVE-2023-0568 | 2023-10-24 | 0:8.0.30-1.el9_2 |
Showing the 25 most recent of 37 that apply to Rocky Linux 9.
AlmaLinux 9source package: php
| CVE | Published | Fixed in package version |
|---|---|---|
| CVE-2026-17543 | 2026-09-01 | 8.2.33-1.module_el9.8.0+303+1bef6c12 |
| CVE-2026-7260 | 2026-09-01 | 8.2.33-1.module_el9.8.0+303+1bef6c12 |
| CVE-2026-14355 | 2026-08-31 | 8.0.30-8.el9_8 |
| CVE-2026-12184 | 2026-07-29 | 8.3.32-1.module_el9.8.0+287+a9a5bb73 |
| CVE-2026-6722 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-6735 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-7258 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-7259 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-7261 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-7262 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2026-7568 | 2026-06-30 | 8.0.30-6.el9_8 |
| CVE-2025-14177 | 2026-02-17 | 8.0.30-5.el9_7 |
| CVE-2025-14178 | 2026-02-17 | 8.0.30-5.el9_7 |
| CVE-2025-1220 | 2026-01-27 | 8.2.30-1.module_el9.7.0+205+fe410f10 |
| CVE-2025-14180 | 2026-01-27 | 8.2.30-1.module_el9.7.0+205+fe410f10 |
| CVE-2025-1735 | 2026-01-27 | 8.2.30-1.module_el9.7.0+205+fe410f10 |
| CVE-2025-6491 | 2026-01-27 | 8.2.30-1.module_el9.7.0+205+fe410f10 |
| CVE-2024-11235 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2025-1217 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2025-1219 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2025-1734 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2025-1736 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2025-1861 | 2025-05-13 | 8.3.19-1.module_el9.6.0+166+f262c21c |
| CVE-2024-11233 | 2025-05-13 | 8.2.28-1.module_el9.6.0+165+cf879a7c |
| CVE-2024-11234 | 2025-05-13 | 8.2.28-1.module_el9.6.0+165+cf879a7c |
Showing the 25 most recent of 46 that apply to AlmaLinux 9.
Advisory data last refreshed 26 September 2026. It is re-read daily.
What this page does not tell you
It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.
It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.
Read next
Find out which of these you are running
One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, PHP included. It changes nothing.