# CVE-2024-9026

## Summary

- **CVE ID:** CVE-2024-9026
- **Severity:** LOW
- **CVSS Score:** 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **CWE:** CWE-158, CWE-117
- **Published:** Oct 8, 2024
- **Last Modified:** Mar 13, 2026

## Description

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

## Affected Products

- PHP Group — PHP (8.1.*)
- PHP Group — PHP (8.2.*)
- PHP Group — PHP (8.3.*)

## References

- [CNA](https://github.com/php/php-src/security/advisories/GHSA-865w-9rf3-2wh5)
- [CVE](https://security.netapp.com/advisory/ntap-20241101-0003/)
- [CVE](https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.49%
- **EPSS Percentile:** 40.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._