The random byte generation function used in the SOAP HTTP Digest authentication code is not checked for failure. This can result in a stack information leak. Furthermore, there's an insufficient number of random bytes used. https://github.com/php/php-src/security/advisories/GHSA-76gg-c692-v2mw
Created php tracking bugs for this issue: Affects: fedora-all [bug 2219296]