Skip to finding
important · Privilege

PHP-FPM's exact-client IPv6 ACL admits any host in an allowed client's /96.

Affects

PHP-FPM, the FastCGI process manager shipped with PHP on Unix-like web servers.

The check compares only 12 of 16 address bytes, so a nearby IPv6 host can pass listen.allowed_clients and submit FastCGI requests to accessible PHP scripts.

Detail and 1 source

Exposure requires an IPv6-reachable TCP listener and an attacker address sharing the configured client's first 96 bits; patched releases exist for every supported branch.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026