| CVE-2026-54133 | mtdowling/jmespath.php | CompilerRuntime code injection via unescaped function names | 18 Aug |
| CVE-2026-67434 | league/commonmark, squizlabs/php_codesniffer | league/commonmark: Denial of service via colliding heading slugs | 6 Aug |
| CVE-2026-71488 | league/commonmark | league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | 6 Aug |
| CVE-2026-71478 | league/commonmark | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded... | 6 Aug |
| CVE-2026-69246 | guzzlehttp/guzzle | Guzzle: Noncanonical host can bypass host-based checks | 3 Aug |
| CVE-2026-69245 | guzzlehttp/guzzle | Guzzle: Noncanonical cookie domain keeps subdomain scope | 3 Aug |
| CVE-2026-65954 | phpcsstandards/phpcsutils | Arbitrary code execution | 27 Jul |
| CVE-2026-59882 | guzzlehttp/psr7 | guzzlehttp/psr7: Host Confusion via Weak URI Host Validation | 21 Jul |
| CVE-2026-67354 | guzzlehttp/guzzle | Guzzle: URI fragments disclosed in redirect Referer headers | 20 Jul |
| CVE-2026-67353 | guzzlehttp/guzzle | Guzzle: Unbounded response cookies risk denial of service | 20 Jul |