Interpretation Conflict Affecting flightphp/core package, versions <3.18.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-FLIGHTPHPCORE-16624485
  • published10 May 2026
  • disclosed6 May 2026
  • creditRootingg

Introduced: 6 May 2026

NewCVE-2026-42551  (opens in a new tab)
CWE-436  (opens in a new tab)

How to fix?

Upgrade flightphp/core to version 3.18.1 or higher.

Overview

Affected versions of this package are vulnerable to Interpretation Conflict via the getMethod function. An attacker can perform unauthorized actions by sending crafted HTTP requests that override the intended HTTP method, potentially bypassing middleware restrictions and escalating privileges.

CVSS Base Scores

version 4.0
version 3.1