Core
- Fixed GH-18695 (zend_ast_export() - float number is not preserved).
- Do not delete main chunk in zend_gc.
- Fix compile issues with zend_alloc and some non-default options.
Curl
- Fix memory leak when setting a list via curl_setopt fails.
- Fix incorrect OpenSSL version detection.
Date
- Fix leaks with multiple calls to DatePeriod iterator current().
FPM
- Fixed GH-18662 (fpm_get_status segfault).
Hash
- Fixed bug GH-14551 (PGO build fails with xxhash).
Intl
- Fix memory leak in intl_datetime_decompose() on failure.
- Fix memory leak in locale lookup on failure.
ODBC
- Fix memory leak on php_odbc_fetch_hash() failure.
Opcache
- Fixed bug GH-18743 (Incompatibility in Inline TLS Assembly on Alpine 3.22).
OpenSSL
- Fix memory leak of X509_STORE in php_openssl_setup_verify() on failure.
- Fixed bug #74796 (Requests through http proxy set peer name).
Phar
- Add missing filter cleanups on phar failure.
- Fixed bug GH-18642 (Signed integer overflow in ext/phar fseek).
PHPDBG
- Fix 'phpdbg --help' segfault on shutdown with USE_ZEND_ALLOC=0.
PDO ODBC
- Fix memory leak if WideCharToMultiByte() fails.
PGSQL
- Fix warning not being emitted when failure to cancel a query with pg_cancel_query().
- Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735)
Random
- Fix reference type confusion and leak in user random engine.
Readline
- Fix memory leak when calloc() fails in php_readline_completion_cb().
Soap
- Fix memory leaks in php_http.c when call_user_function() fails.
- Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP ExtensionAdd commentMore actions via Large XML Namespace Prefix). (CVE-2025-6491)
Standard
- Fixed GHSA-3cr5-j632-f35r (Null byte termination in hostnames). (CVE-2025-1220)
Tidy
- Fix memory leak in tidy output handler on error.
- Fix tidyOptIsReadonly deprecation, using tidyOptGetCategory.