
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring… https://www.cve.org/CVERecord?id=CVE-2026-6104
Post summary
The post references CVE-2026-6104, detailing affected PHP versions and the nature of the vulnerability, but provides no proof of concept, exploit, or patch information.

