The random byte generation function used in the SOAP HTTP Digest authentication code is not checked for failure. This can result in a stack information leak. Furthermore, there's an insufficient number of random bytes used.
https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw