PT-2026-105147 · Bitnami · Php-Min
Published
2026-10-01
·
Updated
2026-10-01
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with an allowed one passes the check and reaches the FastCGI endpoint.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Min