Skip to content

Conversation

@TimWolla
Copy link
Member

This is specifically to import uriparser/uriparser#284 to fix CVE-2025-67899.


@edorian This should be picked for 8.5.1. I didn't adjust NEWS, because I don't know if this will cause issues with the cherry-picking. Let me know if I should do anything (or just push into my branch).

@edorian
Copy link
Member

edorian commented Dec 15, 2025

@TimWolla Thanks for the ping!

Please handle the NEWS as you usually would, and I'll add/pick the entry to 8.5.1 manually.

@TimWolla TimWolla merged commit 284e202 into php:PHP-8.5 Dec 15, 2025
1 check passed
@TimWolla TimWolla deleted the uriparser-cve-2025-67899 branch December 15, 2025 15:19
TimWolla added a commit that referenced this pull request Dec 15, 2025
* PHP-8.5:
  uri: Update to uriparser-0.9.9-85-g9a31011 (#20707)
edorian pushed a commit that referenced this pull request Dec 15, 2025
This is specifically to import uriparser/uriparser#284 to fix CVE-2025-67899.

(cherry picked from commit 284e202)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants