CVE-2026-24894Disclosure(php / frankenphp)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-384CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • frankenphp

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
frankenphp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-12: 2Technical Details · 2026-02-12: 202-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24894 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between r… https://www.cve.org/CVERecord?id=CVE-2026-24894

    Post summary

    CVE-2026-24894 reports a flaw in FrankenPHP where the $_SESSION superglobal is not reset between requests, potentially enabling session fixation attacks.

    00010162
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24894: FrankenPHP's Zombie Sessions: When High Performance Leaks Secrets FrankenPHP, the modern application server that brings Go-like performance to PHP, suffered from a critical session isolation flaw in its worker mode. By failing to corre... https://cvereports.com/reports/CVE-2026-24894

    Post summary

    The post announces a critical session isolation flaw in FrankenPHP's worker mode, but does not provide PoC, exploit, active exploitation, patch, or false‑positive information.

    0000047
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpfrankenphp---

Explore more