FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r3xh-3r3w-47gp FrankenPHP leaks session data between requests in worker mode
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
Description FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Title FrankenPHP leaks session data between requests in worker mode
Weaknesses CWE-269
CWE-384
CWE-613
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-12T20:04:57.869Z

Reserved: 2026-01-27T19:35:20.529Z

Link: CVE-2026-24894

cve-icon Vulnrichment

Updated: 2026-02-12T20:04:54.426Z

cve-icon NVD

Status : Received

Published: 2026-02-12T20:16:10.020

Modified: 2026-02-12T20:16:10.020

Link: CVE-2026-24894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses