The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

The Php Times

Security — Ecosystem

FrankenPHP 1.12.4 – Security & Stability Hardening


FrankenPHP 1.12.4 closes HTTP header spoofing via underscore collision, bundles Caddy 2.11.4 and Mercure 0.24.2 security patches, and fixes worker-mode crashes and data races.

FRANKENPHP RELEASES, July 10, 2026 curated by Heiko

The CGI dash-to-underscore mapping allowed attackers to forge headers; Caddy now strips underscores at server layer. All users should upgrade immediately.

FrankenPHP version 1.12.4 focuses on critical security hardening and stability improvements. A primary fix addresses a vulnerability where CGI's conversion of dashes to underscores in HTTP headers could be exploited for header spoofing. To mitigate this, Caddy now filters underscore characters at the server level.

The release also integrates essential security patches from upstream dependencies, specifically incorporating updates from Caddy 2.11.4 and Mercure 0.24.2. Additionally, the developers have resolved stability issues involving data races and system crashes occurring within the worker mode.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← Ecosystem — Page B1

"All the Code That's Fit to Ship" · The Daily Commit · Screen edition · Imprint · Privacy Policy