
🚀 FrankenPHP 1.12.3 is live! This release focuses heavily on speed, delivering a 7–8% throughput bump for baseline HTTP requests thanks to a refreshed Profile-Guided Optimization (PGO) profile. It also includes a critical security fix for CVE-2026-45062 (CVSS 8.1), resolving an unsafe Unicode handling flaw in CGI path splitting. If you're running v1.11.2 through v1.12.2, you'll want to upgrade soon. Other highlights: • Configurable per-thread max_requests • Cross-platform force-kill primitive for stuck PHP threads • Persistent-zval helpers for cross-thread state • SLSA build-provenance attestations (Verify with: gh attestation verify <binary> --owner php) Release notes: https://github.com/php/frankenphp/releases/tag/v1.12.3
Post summary
The new FrankenPHP 1.12.3 release includes a patch that fixes CVE‑2026‑45062, an unsafe Unicode handling flaw in CGI path splitting, and urges users to upgrade.



