FrankenPHP 1.12.4 – Security & Stability Hardening
FrankenPHP 1.12.4 closes HTTP header spoofing via underscore collision, bundles Caddy 2.11.4 and Mercure 0.24.2 security patches, and fixes worker-mode crashes and data races.
The CGI dash-to-underscore mapping allowed attackers to forge headers; Caddy now strips underscores at server layer. All users should upgrade immediately.
FrankenPHP version 1.12.4 focuses on critical security hardening and stability improvements. A primary fix addresses a vulnerability where CGI's conversion of dashes to underscores in HTTP headers could be exploited for header spoofing. To mitigate this, Caddy now filters underscore characters at the server level.
The release also integrates essential security patches from upstream dependencies, specifically incorporating updates from Caddy 2.11.4 and Mercure 0.24.2. Additionally, the developers have resolved stability issues involving data races and system crashes occurring within the worker mode.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·