Skip to finding
important · Edge — PHP

An IPv6 source inside an allowed /96 can bypass PHP-FPM's exact-client ACL.

Affects

PHP-FPM, the FastCGI process manager used by PHP web servers, when listening on IPv6 TCP and relying on listen.allowed_clients.

The client check compares only 12 address bytes, silently widening an exact IPv6 entry to every source sharing its first 96 bits.

Detail and 3 sources

The reporter demonstrated the bypass against a real php-fpm process, and PHP lists fixed releases dated September 24.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026