[CLSA-2026:1779123668] Fix CVE(s): CVE-2026-6735
Type:
security
Severity:
Moderate
Release date:
2026-05-18 17:01:12 UTC
Description:
* SECURITY UPDATE: XSS via unsanitized request URI in PHP-FPM status page - debian/patches/CVE-2026-6735.patch: escape request_uri with HTML entities in fpm_status_handle_request() for HTML/XML output formats, and fix query_string escape flags in sapi/fpm/fpm/fpm_status.c - CVE-2026-6735
Updated packages:
  • libapache2-mod-php7.4_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:31da2158c24ebac715ba668ff6196193c15eb9ef
  • libphp7.4-embed_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:0d06d889cacac2d99a983fefadd077b1c706a6ee
  • php7.4_7.4.3-4ubuntu2.29+tuxcare.els5_all.deb
    sha:008744153b3f122d3a2236b60822caec9bf96898
  • php7.4-bcmath_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:fa929478ab4b1e7e20127c22c40d25c9ee6db146
  • php7.4-bz2_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:3c193e9b08e7cf74b977a8bdb050a4bc64e9fabb
  • php7.4-cgi_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:09296387ef1f0ff5b5894852e04273652a860c28
  • php7.4-cli_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:c3bb7826150cb387f8cf3b927e344d0f14284091
  • php7.4-common_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:c7dc98e422b5475d9722f49e60c1bb37b0248dcb
  • php7.4-curl_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:c6d6b03910020063711989385881ea9cb1747192
  • php7.4-dba_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:f672512b290e440c1829f3bd4169175a85ed5b56
  • php7.4-dev_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:05136fb1ddefbb3a54a04e4a88e5ce58491ac48f
  • php7.4-enchant_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:ea54fbde0b01dd8efdc30b3b2f6b34882f560744
  • php7.4-fpm_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:183d5dcaaa250246a5abcfd1d62968ea87122c16
  • php7.4-gd_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:2b56bf8248edd4beffa191bad3c01e355a5cf5d6
  • php7.4-gmp_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:0ada2bbbfb101d2d10025d2de242daf2c66629d9
  • php7.4-imap_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:bfd1347050087e70d52273e80ee81259a78c23d2
  • php7.4-interbase_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:ac213c2f8140f4399382ea2067bd1b9d12e2fd77
  • php7.4-intl_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:bfa9befc67eadf2a1e2875340181b46d5cbe2d6a
  • php7.4-json_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:f25a5b3f06fb92aad227d3d1b83353097cadce39
  • php7.4-ldap_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:48bd5a5616f76fc4d78e3d3c81645e79bf563715
  • php7.4-mbstring_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:5f35add9d17a39d96b0695e6c3efa9be64aaf86f
  • php7.4-mysql_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:1e045e50998a2ec9a8da935fbcc048869792810d
  • php7.4-odbc_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:01120183931fa9955cf63726eafd8a0c5a1e8208
  • php7.4-opcache_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:f9e4cd095f067050d2f066fb64e7b251e7bbbbd8
  • php7.4-pgsql_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:4347c21b5230ebb3b5a036218186b0c50f6e4b01
  • php7.4-phpdbg_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:9f3f58943a349e029166dace4f1dc36a5f072b61
  • php7.4-pspell_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:65dee81d475c8e5d384c2990c2ff683187d0b0b6
  • php7.4-readline_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:99ac2deb78fd4d53900a267e7401a5bc1d7f4c15
  • php7.4-snmp_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:6f04e63303a4aff9c7726a4b5802c64c828acb25
  • php7.4-soap_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:f991754261764ac30c4682995518d6190d9d9bf1
  • php7.4-sqlite3_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:9168116ce4f929d1ff07b315d91b5a6cf00443bd
  • php7.4-sybase_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:abf2fa9f1ed08c78199b4bb863e691252d16795f
  • php7.4-tidy_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:0fdd4e7529a880ee23eed1a8b79af3f1b073cb7d
  • php7.4-xml_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:1c494d40e94a71d338bb620000a1b1eaf0323169
  • php7.4-xmlrpc_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:d2505bcd42d67d6fc60dee1d2a3f9e518c6033e1
  • php7.4-xsl_7.4.3-4ubuntu2.29+tuxcare.els5_all.deb
    sha:054ef935ab52844dd18af263a77f2509155618ab
  • php7.4-zip_7.4.3-4ubuntu2.29+tuxcare.els5_amd64.deb
    sha:69ee292658432a3d61993fbd5794ee8aa4dc1fc5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.