FILTER_VALIDATE_URL accepts URLs with invalid userinfo (CVE-2020-7071).
stream_get_contents() fails with maxlength=-1 or default.
See upstream releasenotes for other changes.
- https://bugs.mageia.org/show_bug.cgi?id=28036
- https://www.php.net/ChangeLog-7.php#PHP_7_3_26
- https://www.cve.org/CVERecord?id=CVE-2020-7071
- 7/core/php-7.3.26-1.mga7
Get the latest Linux and open source security news straight to your inbox.