Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3920-1 | php7.4 security update | 
  EUVD | 
                EUVD-2024-49671 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability. | 
  Ubuntu USN | 
                USN-7049-1 | PHP vulnerabilities | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Tue, 19 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | ||
| Vendors & Products | 
        
        Php-fpm
         Php-fpm php-fpm  | 
    
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Thu, 12 Dec 2024 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9  | 
|
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux  | 
Wed, 16 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Php-fpm
         Php-fpm php-fpm  | 
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:php-fpm:php-fpm:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Php-fpm
         Php-fpm php-fpm  | 
Wed, 09 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Tue, 08 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Php
         Php php  | 
|
| CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Php
         Php php  | 
|
| Metrics | 
        
        ssvc
         
  | 
Tue, 08 Oct 2024 04:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability. | |
| Title | PHP-FPM logs from children may be altered | |
| Weaknesses | CWE-117 CWE-158  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-11-03T22:33:15.254Z
Reserved: 2024-09-20T00:15:42.321Z
Link: CVE-2024-9026
Updated: 2024-10-08T12:49:08.252Z
Status : Modified
Published: 2024-10-08T04:15:11.060
Modified: 2025-11-03T23:17:33.343
Link: CVE-2024-9026
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 EUVD
 Ubuntu USN