A flaw in PHP’s PostgreSQL driver shows how emulated prepares can turn a routine parameter path into a process-level denial of service.
A pair of high-severity flaws in PHP’s database layer underline a familiar danger in web security: when a driver misreads memory or bytes, the result can be a crash or a SQL injection path, even in code that looks ordinary.