FastCGI Security Flaw in PHP Affects IPv6 Address Validation
CVE-2026-91768
6.5MEDIUM
What is CVE-2026-91768?
The FastCGI component in PHP has a vulnerability in its IPv6 address validation mechanism. It inadequately compares the first 12 bytes of a 16-byte IPv6 address, allowing an attacker with an address that shares the initial 96 bits with an allowed address to bypass security checks. This can lead to unauthorized access to FastCGI endpoints, presenting significant risks for web application security. Proper configuration and prompt updates are essential to mitigate the exposure.
Affected Version(s)
PHP 8.2.* < 8.2.34
PHP 8.3.* < 8.3.35
PHP 8.4.* < 8.4.26
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
@l8BL (GitHub)
@OSTIF-Derek (GitHub)
Ilia Alshanetsky
Alexandre Daubois
Arnaud Le Blanc
Jakub Zelenka
