FILTER_SANITIZE_ENCODED does not encode 0xFF IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison Various packet overreads in mysqlnd wire protocol TLS hostname verification falls back to CN after SAN mismatch Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN Integer overflow in phar_tar_number() allowing TAR archive entry injection Unbounded recursion in server-side cleanup_xml_node() Integer overflow to buffer overflow in SOAP HTTP parsing) Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL ross-origin credential leak in HTTP stream wrapper redirects Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header