CVE-2026-24894 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset bet…
High CVSS: 8.7

CVE-2026-24894

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Vendor
Php
Product
Frankenphp
CWE
CWE-269
Yayın Tarihi
2026-02-12 20:16:10
Güncelleme
2026-02-20 18:31:06
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar