AI description
CVE-2026-91768 describes an IPv6 access control bypass vulnerability found in PHP-FPM. This flaw specifically affects the `listen.allowed_clients` configuration due to a partial address comparison mechanism. The vulnerability allows clients to circumvent intended IPv6 Access Control List (ACL) restrictions. This issue has been noted in the context of unpatched Linux distributions, including Debian Linux, and is associated with PHP versions such as php8.2 and php8.4. It is also listed among multiple vulnerabilities affecting PHP 8.3.x versions prior to 8.3.35.
- Description
- The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.
- Source
- security@php.net
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@php.net
- CWE-1023
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16
PHP 8.4.26 released - 64 fixes in 25 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/ZrPmRpxg1x
@php_net
26 Sept 2026
2637 Impressions
9 Retweets
30 Likes
3 Bookmarks
0 Replies
1 Quote
CVE-2026-91768 The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix inste… https://t.co/Z2JaPT5rB4
@CVEnew
26 Sept 2026
589 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PHP 8.2.34 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/Or4opPr46m
@php_net
25 Sept 2026
4236 Impressions
4 Retweets
22 Likes
1 Bookmark
0 Replies
0 Quotes
PHP 8.3.35 released - 12 fixes in 8 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/V3HAM01AXX
@php_net
25 Sept 2026
3811 Impressions
6 Retweets
28 Likes
3 Bookmarks
0 Replies
0 Quotes
PHP 8.5.11 released - 57 fixes in 22 components, including security fixes (CVE-2026-91768, CVE-2025-1218, CVE-2026-91769). Changelog + downloads: https://t.co/sJtYkJM8Hd
@php_net
24 Sept 2026
4391 Impressions
13 Retweets
47 Likes
7 Bookmarks
0 Replies
0 Quotes