XSS within PHP-FPM status endpoint
Published May 10, 2026
7.3
HIGHCVSS 4.0
EPSS 0.31%
Description
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
Affected products
-
Affected
- ≥ 8.2.*, < 8.2.31
- ≥ 8.3.*, < 8.3.31
- ≥ 8.4.*, < 8.4.21
- ≥ 8.5.*, < 8.5.6
No data.
Red Hat Enterprise Linux 10
php-0:8.3.31-1.el10_2
Fixed · RHSA-2026:23388
Red Hat Enterprise Linux 10
php8.4-0:8.4.21-1.el10_2
Fixed · RHSA-2026:22649
Red Hat Enterprise Linux 8
php:7.4-8100020260604072603.f7998665
Fixed · RHSA-2026:34354
Red Hat Enterprise Linux 8
php:8.2-8100020260521052503.f7998665
Fixed · RHSA-2026:22305
Red Hat Enterprise Linux 9
php-0:8.0.30-6.el9_8
Fixed · RHSA-2026:33449
Red Hat Enterprise Linux 9
php:8.2-9080020260521080715.9
Fixed · RHSA-2026:22143
Red Hat Enterprise Linux 9
php:8.3-9080020260521113736.9
Fixed · RHSA-2026:22142
Red Hat Hardened Images
php-main-8.5.6-1.hum1
Fixed · RHSA-2026:14125
Red Hat Enterprise Linux 6
php
Fix deferred
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php-0:8.3.31-1.el10_2 | Fixed | RHSA-2026:23388 |
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.21-1.el10_2 | Fixed | RHSA-2026:22649 |
| Red Hat Enterprise Linux 8 | php:7.4-8100020260604072603.f7998665 | Fixed | RHSA-2026:34354 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260521052503.f7998665 | Fixed | RHSA-2026:22305 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-6.el9_8 | Fixed | RHSA-2026:33449 |
| Red Hat Enterprise Linux 9 | php:8.2-9080020260521080715.9 | Fixed | RHSA-2026:22143 |
| Red Hat Enterprise Linux 9 | php:8.3-9080020260521113736.9 | Fixed | RHSA-2026:22142 |
| Red Hat Hardened Images | php-main-8.5.6-1.hum1 | Fixed | RHSA-2026:14125 |
| Red Hat Enterprise Linux 6 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Restrict network access to the PHP-FPM status page to trusted internal networks or localhost. This can be achieved by configuring web server access controls (e.g., Apache httpd or Nginx) to deny external access to the status page URL. If the PHP-FPM status page functionality is not required, it should be disabled in the PHP-FPM configuration. Any changes to web server or PHP-FPM configuration may require a service reload or restart to take effect.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6735 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468562 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28967 Advisory
- https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv ExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6735
- https://www.cve.org/CVERecord?id=CVE-2026-6735
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6735 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2468562 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28967 | Advisory | |
| https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv | ExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6735 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6735 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data