Key details

  1. FrankenPHP v1.13.0 was released October 4, 2026.
  2. Five security vulnerabilities are fixed, two rated high by the maintainers.
  3. A Windows SCRIPT_FILENAME document-root escape and dot-form header spoofing are among the high-severity issues.
  4. Configuration reloads validate before replacing the running service.
  5. Caddy 2.11.7 and Mercure 1.0 are bundled.
  6. Thread accounting, header limits, timeouts and Mercure auth rules may require migration.

What builders should take away

  1. Prioritise patching exposed FrankenPHP instances, especially on Windows and with untrusted HTTP inputs.
  2. Test thread budgets, worker counts and Caddy header/timeout behaviour in staging.
  3. Review Mercure issuer configuration and hot-reload client URLs before deployment.
  4. Use safe reload validation and keep rollback plans for worker-mode production workloads.

What changed

FrankenPHP 1.13.0 released October 4, 2026, fixes five vulnerabilities including a high-severity Windows SCRIPT_FILENAME document-root escape, high-severity header spoofing via dot-form header names, CGI path-segment parsing that could execute the wrong PHP file, process-environment leakage between threads through putenv(), and a crafted-array crash in frankenphp_log(). It upgrades to Caddy 2.11.7, includes Mercure 1.0, and validates new configurations before swapping them into a running server. New default header-size/timeouts, thread accounting and Mercure configuration rules can require deployment changes.

Why it matters

A PHP application server runs untrusted HTTP requests and often multiplexes multiple application workers in one process. The security fixes affect isolation, path resolution and request trust boundaries, while the reload change prevents invalid config from replacing a working service. Operators must balance patch urgency with real compatibility changes: worker thread budgets, HTTP header treatment and Mercure auth config can alter behaviour after an upgrade.

Five distinct security issues affect request boundaries

The release closes document-root escape on Windows, dot-header spoofing, unsafe CGI path splitting, process-wide environment leakage and a crafted log-array crash. Two are classified high by the project.

Reload validation prevents avoidable outages

FrankenPHP now rejects invalid configuration before replacing the running config; the project exposes a Validate() API for library users.

Caddy and Mercure introduce operational changes

Caddy 2.11.7 adds Slowloris protection, URLPattern matching, Incremental streaming and SSE fixes. Mercure 1.0 changes issuer binding and hot-reload URL conventions.

Check thread and header defaults before deploying

num_threads now counts ordinary-request threads separately from worker threads. A too-low max_threads can fail startup, and Caddy now defaults to 16 KiB request headers and one-minute stalled-read/write timeouts.

What to watch next

  • Further security advisories or regressions from 1.13.0.
  • Downstream hosting/image rebuild adoption.
  • Mercure 1.0 and Caddy default-compatibility reports.

Still unclear

  • Severity and exploitability vary by deployment platform and configuration.
  • No widespread exploitation was established by the release notes.
  • Configuration defaults can be overridden; operators must audit actual effective settings.

Sources

Direct reading behind this dossier.

1 sources

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment