CVE-2026-24894
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Vendor
Product
CWE
Yayın Tarihi
2026-02-12 20:16:10
Güncelleme
2026-02-20 18:31:06
Source Identifier
security-advisories@github.com
KEV Date Added
-