Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-24894. PoCs published by dwisiswant0.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2026-24894, demonstrating cross-request session data leakage in FrankenPHP versions prior to 1.11.2. The exploit includes a detailed analysis, a vulnerable Dockerized application, and a Python script to reproduce the session data leak.
Description
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
Exploits (1)
This repository contains a functional exploit PoC for CVE-2026-24894, demonstrating cross-request session data leakage in FrankenPHP versions prior to 1.11.2. The exploit includes a detailed analysis, a vulnerable Dockerized application, and a Python script to reproduce the session data leak.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N