CVE-2026-24894
EUVD-2026-669812.02.2026, 20:16
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| php | frankenphp | 𝑥 < 1.11.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration