What changed
FrankenPHP 1.13.0 released October 4, 2026, fixes five vulnerabilities including a high-severity Windows SCRIPT_FILENAME document-root escape, high-severity header spoofing via dot-form header names, CGI path-segment parsing that could execute the wrong PHP file, process-environment leakage between threads through putenv(), and a crafted-array crash in frankenphp_log(). It upgrades to Caddy 2.11.7, includes Mercure 1.0, and validates new configurations before swapping them into a running server. New default header-size/timeouts, thread accounting and Mercure configuration rules can require deployment changes.
Why it matters
A PHP application server runs untrusted HTTP requests and often multiplexes multiple application workers in one process. The security fixes affect isolation, path resolution and request trust boundaries, while the reload change prevents invalid config from replacing a working service. Operators must balance patch urgency with real compatibility changes: worker thread budgets, HTTP header treatment and Mercure auth config can alter behaviour after an upgrade.
Five distinct security issues affect request boundaries
The release closes document-root escape on Windows, dot-header spoofing, unsafe CGI path splitting, process-wide environment leakage and a crafted log-array crash. Two are classified high by the project.
Reload validation prevents avoidable outages
FrankenPHP now rejects invalid configuration before replacing the running config; the project exposes a Validate() API for library users.
Caddy and Mercure introduce operational changes
Caddy 2.11.7 adds Slowloris protection, URLPattern matching, Incremental streaming and SSE fixes. Mercure 1.0 changes issuer binding and hot-reload URL conventions.
Check thread and header defaults before deploying
num_threads now counts ordinary-request threads separately from worker threads. A too-low max_threads can fail startup, and Caddy now defaults to 16 KiB request headers and one-minute stalled-read/write timeouts.