FrankenPHP version 1.12.4 focuses on critical security hardening and stability improvements. A primary fix addresses a vulnerability where CGI's conversion of dashes to underscores in HTTP headers could be exploited for header spoofing. To mitigate this, Caddy now filters underscore characters at the server level.

The release also integrates essential security patches from upstream dependencies, specifically incorporating updates from Caddy 2.11.4 and Mercure 0.24.2. Additionally, the developers have resolved stability issues involving data races and system crashes occurring within the worker mode.