FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
History

Thu, 12 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
Description FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Title FrankenPHP leaks session data between requests in worker mode
Weaknesses CWE-269
CWE-384
CWE-613
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-12T19:12:04.387Z

Updated: 2026-02-12T20:04:57.869Z

Reserved: 2026-01-27T19:35:20.529Z

Link: CVE-2026-24894

cve-icon Vulnrichment

Updated: 2026-02-12T20:04:54.426Z

cve-icon NVD

Status : Received

Published: 2026-02-12T20:16:10.020

Modified: 2026-02-12T20:16:10.020

Link: CVE-2026-24894

cve-icon Redhat

No data.