github.com/dunglas/frankenphp
🧟 The modern PHP app server
Activity
- Latest release
- 1mo ago
- Total releases
- 52
- Cadence
- ~17 days
- Last 12 months
- 14
Reach
- Stars
- 11.3k
Details
- First release
- Sep 20, 2023
| Version | Released | |
|---|---|---|
v1.12.7
patch
1 CVE
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.7
patch
Dependencies (7)
|
|
v1.12.6
patch
1 CVE
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.6
patch
Dependencies (7)
|
|
v1.12.5
patch
1 CVE
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.5
patch
Dependencies (7)
|
|
v1.12.4
patch
1 CVE
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.4
patch
Dependencies (7)
|
|
v1.12.3
patch
1 CVE
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.3
patch
Dependencies (7)
|
|
v1.12.2
patch
2 CVEs
CVE-2026-45062
GO-2026-5084
GHSA-3g8v-8r37-cgjm
Jun 25, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp Fixed in
1.12.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.2
patch
Dependencies (8)
|
|
v1.12.1
patch
2 CVEs
CVE-2026-45062
GO-2026-5084
GHSA-3g8v-8r37-cgjm
Jun 25, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp Fixed in
1.12.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.1
patch
Dependencies (8)
|
|
v1.12.0
minor
2 CVEs
CVE-2026-45062
GO-2026-5084
GHSA-3g8v-8r37-cgjm
Jun 25, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp Fixed in
1.12.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.12.0
minor
Dependencies (8)
|
|
v1.11.3
patch
2 CVEs
CVE-2026-45062
GO-2026-5084
GHSA-3g8v-8r37-cgjm
Jun 25, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp Fixed in
1.12.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.11.3
patch
Dependencies (8)
|
|
v1.11.2
patch
2 CVEs
CVE-2026-45062
GO-2026-5084
GHSA-3g8v-8r37-cgjm
Jun 25, 2026
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files in github.com/dunglas/frankenphp Fixed in
1.12.3
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.11.2
patch
Dependencies (8)
|
|
v1.11.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.11.1
patch
Dependencies (7)
|
|
v1.11.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.11.0
minor
Dependencies (7)
|
|
v1.10.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.10.1
patch
Dependencies (8)
|
|
v1.10.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.10.0
minor
Dependencies (8)
|
|
v1.9.1
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.9.1
minor
Dependencies (7)
|
|
v1.9.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.9.0
minor
Dependencies (7)
|
|
v1.8.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (7)
|
|
v1.7.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (6)
|
|
v1.6.2
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (6)
|
|
v1.6.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.6.1
patch
Dependencies (6)
|
|
v1.6.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (6)
|
|
v1.5.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (5)
|
|
v1.4.4
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.4.4
patch
Dependencies (5)
|
|
v1.4.3
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (5)
|
|
v1.4.2
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (5)
|
|
v1.4.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (5)
|
|
v1.4.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (5)
|
|
v1.3.6
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.6
patch
Dependencies (5)
|
|
v1.3.5
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (8)
|
|
v1.3.4
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (8)
|
|
v1.3.3
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.3
patch
Dependencies (5)
|
|
v1.3.2
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (5)
|
|
v1.3.1
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (5)
|
|
v1.2.5
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (4)
|
|
v1.2.4
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (4)
|
|
v1.2.2
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (4)
|
|
v1.2.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (4)
|
|
v1.2.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (4)
|
|
v1.1.5
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.5
patch
Dependencies (4)
|
|
v1.1.4
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (4)
|
|
v1.1.3
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (4)
|
|
v1.1.2
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (4)
|
|
v1.1.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (4)
|
|
v1.1.0
minor
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (3)
|
|
v1.0.3
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (3)
|
|
v1.0.1
patch
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.1
patch
Dependencies (3)
|
|
v1.0.0
initial
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.0
initial
Dependencies (3)
|
|
v1.0.0-rc.4
pre
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (3)
|
|
v1.0.0-rc.2
pre
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.0-rc.2
pre
Dependencies (3)
|
|
v1.0.0-beta.2
pre
3 CVEs
CVE-2026-24895
GO-2026-4486
GHSA-g966-83w7-6w38
Feb 17, 2026
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2026-24894
GO-2026-4489
GHSA-r3xh-3r3w-47gp
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp FrankenPHP leaks session data between requests in worker mode in github.com/dunglas/frankenphp Fixed in
1.11.2
References Updated Feb 19, 2026 · Source: OSV.dev
GO-2026-4442
GHSA-x9p2-77v6-6vhf
Feb 17, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp FrankenPHP has delayed propagation of security fixes in upstream base images in github.com/dunglas/frankenphp. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/dunglas/frankenphp before v1.1.11. Updated Feb 19, 2026 · Source: OSV.dev |
v1.0.0-beta.2
pre
Dependencies (3)
|