FastCGI Security Flaw in PHP Affects IPv6 Address Validation
CVE-2026-91768

6.5MEDIUM

Key Information:

Vendor

PHP Group

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-91768?

The FastCGI component in PHP has a vulnerability in its IPv6 address validation mechanism. It inadequately compares the first 12 bytes of a 16-byte IPv6 address, allowing an attacker with an address that shares the initial 96 bits with an allowed address to bypass security checks. This can lead to unauthorized access to FastCGI endpoints, presenting significant risks for web application security. Proper configuration and prompt updates are essential to mitigate the exposure.

Affected Version(s)

PHP 8.2.* < 8.2.34

PHP 8.3.* < 8.3.35

PHP 8.4.* < 8.4.26

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@l8BL (GitHub)
@OSTIF-Derek (GitHub)
Ilia Alshanetsky
Alexandre Daubois
Arnaud Le Blanc
Jakub Zelenka
.