The PHP development team announces the immediate availability of PHP 7.0.9.
This is a security release. Several security bugs were fixed in this
release, including the HTTP_PROXY issue.
All PHP 7.0 users are encouraged to upgrade to this version.
For source downloads of PHP 7.0.9 please visit our downloads page: php.net/downloads.php
Manuel Lemos - 2016-07-21 17:53:19 - In reply to message 1 from Stefan Jibrail Froelich
Great. That was what I expected, even though it is not a vulnerability in PHP itself, it is better to protect applications that use libraries which check the HTTP_PROXY variable. The potential of abuse of those libraries is huge.
It seems PHP 5.5 and PHP 5.6 will also be fixed soon.