CVE-2026-24895Disclosure(php / frankenphp)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the original path. Because strings.ToLower() in Go can increase the byte length of certain UTF-8 characters (e.g., Ⱥ expands when lowercased), the computed index may not align with the correct position in the original string. This results in an incorrect SCRIPT_NAME and SCRIPT_FILENAME, potentially causing FrankenPHP to execute a file other than the one intended by the URI. This vulnerability is fixed in 1.11.2.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-180

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • frankenphp

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
frankenphp

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-16: 1PoC Mentioned / Linked · 2026-02-16: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-16: 102-1202-1302-16
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-02-131
Disclosure1
2026-02-161
PoC1
Full discourse3 posts
  • PentesterLab@PentesterLab
    PoC

    New lab: CVE-2026-24895 — FrankenPHP Path Confusion RCE (Unicode) People think "lowercase it" is harmless. In Unicode it’s not. Case folding can do weird mappings (Turkish i, Kelvin sign…), and sometimes worse: UTF-8 byte length changes. FrankenPHP < 1.11.2 did strings.ToLower(path) then used the byte index of ".php" from the lowered string to split the original path. If ToLower() expands bytes → index mismatch → split shifts → SCRIPT_FILENAME can become shell.php.txt → PHP executes the uploaded .txt. Hands-on lab: https://pentesterlab.com/exercises/cve-2026-24895

    Post summary

    The post introduces the CVE-2026-24895 vulnerability in FrankenPHP, explains the Unicode case‑folding flaw that enables RCE, and provides a lab link for hands‑on exploitation, highlighting the existence of a PoC.

    17061315.0K
    199.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24895 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion… https://www.cve.org/CVERecord?id=CVE-2026-24895

    Post summary

    CVE-2026-24895 is a disclosed Unicode handling flaw in FrankenPHP’s CGI path splitting logic prior to version 1.11.2, with no evidence of PoC, exploitation, or patch information provided.

    00020178
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24895 Unicode Path Splitting Vulnerability in FrankenPHP CGI Before 1.11.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24895

    Post summary

    The text announces a Unicode Path Splitting vulnerability in FrankenPHP CGI before 1.11.2, but provides no PoC, exploit code, or patch information.

    0001064
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpfrankenphp---

Explore more