Back

HIGH

XSS within PHP-FPM status endpoint

Published May 10, 2026

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Affected products

Remediation

Red Hat mitigation

Restrict network access to the PHP-FPM status page to trusted internal networks or localhost. This can be achieved by configuring web server access controls (e.g., Apache httpd or Nginx) to deny external access to the status page URL. If the PHP-FPM status page functionality is not required, it should be disabled in the PHP-FPM configuration. Any changes to web server or PHP-FPM configuration may require a service reload or restart to take effect.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner php
Published May 10, 2026
Updated May 11, 2026
Reserved Apr 21, 2026

CISA Vulnrichment

Updated May 11, 2026

NVD

Status Analyzed
Modified Jul 24, 2026

Red Hat

Severity Moderate
Public date May 10, 2026
Bugzilla 2468562

ENISA EUVD

Assigner php
Published May 10, 2026
Updated May 11, 2026

GitHub

No data