
CVE-2026-24894 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between r… https://www.cve.org/CVERecord?id=CVE-2026-24894
Post summary
CVE-2026-24894 reports a flaw in FrankenPHP where the $_SESSION superglobal is not reset between requests, potentially enabling session fixation attacks.

