
CVE-2026-42551 Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_me… https://www.cve.org/CVERecord?id=CVE-2026-42551
Post summary
The text discloses that CVE-2026-42551 allows the Flight PHP framework (pre‑3.18.1) to honor the X-HTTP-Method-Override header unconditionally, potentially leading to method spoofing, but no countermeasures or exploit code are offered.
