[php-src] PHP-8.5: [ci skip] add CVE ref

Remi Collet <[email protected]>
Newsgroups gmane.comp.php.cvs.general
Message-ID <[email protected]>
Author: Remi Collet (remicollet)
Date: 2026-07-08T09:02:00+02:00

Commit: https://github.com/php/php-src/commit/735748f5d72cb835c46f785eee2fc32fe5a1dccf
Raw diff: https://github.com/php/php-src/commit/735748f5d72cb835c46f785eee2fc32fe5a1dccf.diff

[ci skip] add CVE ref

Changed paths:
  M  NEWS


Diff:

diff --git a/NEWS b/NEWS
index 2f00f144fbb8..e6178c04c988 100644
--- a/NEWS
+++ b/NEWS
@@ -140,7 +140,7 @@ PHP                                                                        NEWS
 
 - OpenSSL:
   . Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in
-    openssl_encrypt with AES-WRAP-PAD). (David Carlier)
+    openssl_encrypt with AES-WRAP-PAD). (CVE-2026-14355) (David Carlier)
 
 - Phar:
   . Fixed a bypass of the magic ".phar" directory protection in
@@ -327,7 +327,7 @@ PHP                                                                        NEWS
 
 - Streams:
   . Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL
-    and a proxy set). (ndossche)
+    and a proxy set). (CVE-2026-12184) (ndossche)
 
 - URI:
   . Fixed CVE-2026-42371 (uriparser before 1.0.1 has numeric truncation in
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.