important · Edge — PHP
An IPv6 source inside an allowed /96 can bypass PHP-FPM's exact-client ACL.
Affects
PHP-FPM, the FastCGI process manager used by PHP web servers, when listening on IPv6 TCP and relying on listen.allowed_clients.
The client check compares only 12 address bytes, silently widening an exact IPv6 entry to every source sharing its first 96 bits.
Detail and 3 sources
The reporter demonstrated the bypass against a real php-fpm process, and PHP lists fixed releases dated September 24.