CVE-2026-24895 | php franken up to 1.11.1 Unicode Character ToLower incorrect behavior order: validate before canonicalize (GHSA-g966-83w7-6w38)
A vulnerability described as critical has been identified in php franken up to 1.11.1. This affects the function ToLower of the component Unicode Character Handler. The manipulation results in incorrect behavior order: validate before canonicalize.
This vulnerability was named CVE-2026-24895. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.