
CVE-2026-42552 Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the full exception message, exception code, and st… https://www.cve.org/CVERecord?id=CVE-2026-42552
Post summary
CVE-2026-42552 reveals that Flight prior to 3.18.1 leaks full exception messages via its error handler, but the bug has been fixed in 3.18.1.
