It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information leak or use of weak randomness. Ref: https://packetstormsecurity.com/files/172900/dsa-5424-1.txt
PHP upstream considers this issue as "low", so don't issue any CVE for it
Notice: this issue is https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw Was assigned CVE-2023-3247 Was fixed in 8.0.29, 8.1.20 and 8.2.7