cvedb.io
CVE-2026-24894
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-02-12T20:16:10.020 · Last modified 2026-06-17T10:23:45.887

Summary

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.

Affected products

php — frankenphp

Does this affect you?

Add your gear to cvedb and we'll alert you only when php ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.