@buherator If it’s not in a remote surface (multipart parsing, json, etc) they won’t assign any CVE to it. Would need to check but it’s likely tracked as a functional issue publicly.
@buherator IIRC you get a GHSA ID every time you report something through https://github.com/php/php-src/security/, so this one must have been closed as N/A because it's now in https://github.com/php/php-src/issues/18209.
Anyway it's a nice writeup, and apparently a stable bug that will be useful to bypass disable_functions on a bunch of PHP releases!