CVE-2026-45062Patch

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a non-.php file as a .php script. In any deployment where the attacker can place content into a file served by FrankenPHP (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This issue has been patched in version 1.12.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-176CWE-178

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-16); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-16: 2Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-16: 2Patch / Workaround · 2026-05-17: 1Technical Details · 2026-05-16: 2Technical Details · 2026-05-17: 105-1605-1705-18
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-162
Patch2
2026-05-171
Patch1
2026-05-181
General1
Full discourse4 posts
  • Kévin Dunglas@dunglas
    Patch

    🚀 FrankenPHP 1.12.3 is live! This release focuses heavily on speed, delivering a 7–8% throughput bump for baseline HTTP requests thanks to a refreshed Profile-Guided Optimization (PGO) profile. It also includes a critical security fix for CVE-2026-45062 (CVSS 8.1), resolving an unsafe Unicode handling flaw in CGI path splitting. If you're running v1.11.2 through v1.12.2, you'll want to upgrade soon. Other highlights: • Configurable per-thread max_requests • Cross-platform force-kill primitive for stuck PHP threads • Persistent-zval helpers for cross-thread state • SLSA build-provenance attestations (Verify with: gh attestation verify <binary> --owner php) Release notes: https://github.com/php/frankenphp/releases/tag/v1.12.3

    Post summary

    The new FrankenPHP 1.12.3 release includes a patch that fixes CVE‑2026‑45062, an unsafe Unicode handling flaw in CGI path splitting, and urges users to upgrade.

    1160102115.3K
    14.3K followersView on X
  • Jay Rogers 👨‍💻@jaydrogers
    Patch

    🚨 More security updates for serversideup/php: FrankenPHP to v1.12.3, which addresses CVE-2026-45062 (high, CVSS 8.1). If you upgraded to v4.4.0 earlier, move to v4.4.1 ASAP. This addresses a GitHub release bug too 🙃 https://github.com/serversideup/docker-php/releases/tag/v4.4.1

    Post summary

    The post announces an update to FrankenPHP v1.12.3 that patches CVE-2026-45062, and also recommends updating to docker-php v4.4.1, without mentioning active exploitation or PoC details.

    1302632.0K
    3.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-45062. 0day Intel: 🚀 FrankenPHP 1.12.3 is live! This release focuses heavily on speed, delivering

    Post summary

    The entry notes CVE-2026-45062 and states that FrankenPHP 1.12.3 is live, but provides no specific details on exploitation, patching, or vulnerability characteristics.

    1000058
    226 followersView on X
  • Securelens@securelens
    Patch

    frankenphp (cgi.go) misuses http://golang.org/x/text/search unicode folding to match non-.php filenames as .php, allowing RCE if an attacker can upload a file. CVE-2026-45062, patched in 1.12.3. #php https://github.com/advisories/GHSA-3g8v-8r37-cgjm

    Post summary

    CVE-2026-45062 in frankenphp's cgi.go was identified as an RCE via filename folding, and a patch (1.12.3) has been released; no exploitation or PoC details are provided.

    0000021
    8 followersView on X

Explore more