{"id":"GHSA-vxrr-w42w-w76g","summary":"Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass","details":"### Summary\n`Request::getMethod()` unconditionally honors the `X-HTTP-Method-Override` header and the `$_REQUEST['_method']` parameter on **any** HTTP verb (including safe verbs such as GET), with no opt-in and no whitelist of permitted target methods. A GET request can silently become a DELETE or PUT, enabling CSRF escalation against destructive endpoints, bypass of middleware gated on unsafe verbs, and cache poisoning between CDN and origin.\n\n### Affected code\n`flight/net/Request.php` (≈ lines 281-292):\n\n```php\npublic static function getMethod(): string\n{\n    $method = self::getVar('REQUEST_METHOD', 'GET');\n    if (self::getVar('HTTP_X_HTTP_METHOD_OVERRIDE') !== '') {\n        $method = self::getVar('HTTP_X_HTTP_METHOD_OVERRIDE');\n    } elseif (isset($_REQUEST['_method']) === true) {\n        $method = $_REQUEST['_method'];\n    }\n    return strtoupper($method);\n}\n```\n\n`$_REQUEST` aggregates `$_GET` and `$_POST`; on PHP runtimes with `request_order=GPC` it also includes `$_COOKIE`.\n\n### Proof of concept\n```\nGET /item/42?_method=DELETE        HTTP/1.1\n```\nis dispatched as `DELETE /item/42`.\n\n```\nGET /item/42                       HTTP/1.1\nX-HTTP-Method-Override: DELETE\n```\nis also dispatched as `DELETE /item/42`.\n\nTrivial CSRF vector (no JavaScript required):\n```html\n\u003cimg src=\"https://victim.tld/item/42?_method=DELETE\"\u003e\n```\nloaded on any attacker-controlled page triggers the destructive DELETE on page load, bypassing Same-Origin Policy (image loads are not blocked).\n\nReproduced against `/poc4/item/42`.\n\n### Impact\n- GET → DELETE / PUT CSRF on any route registered for unsafe verbs.\n- Bypass of authentication, CSRF token, or rate-limiting middleware that is gated only on POST/DELETE.\n- CDN cache poisoning: the CDN caches the GET response body while the origin executed a DELETE.\n\n### Patch (fixed in `3.18.1`, commit `b8dd23a`)\nA new `flight.allow_method_override` setting controls both override vectors. Operators can set it to `false` to disable `X-HTTP-Method-Override` and `_method` entirely.\n\n### Credit\nDiscovered by **@Rootingg**.","aliases":["CVE-2026-42551"],"modified":"2026-05-14T20:52:31.715224Z","published":"2026-05-06T21:38:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-06T21:38:16Z","nvd_published_at":"2026-05-13T20:16:22Z","cwe_ids":["CWE-436"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/flightphp/core/security/advisories/GHSA-vxrr-w42w-w76g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42551"},{"type":"WEB","url":"https://github.com/flightphp/core/commit/b8dd23aaa828cb289fa3c84e75b2a3717cab50b0"},{"type":"PACKAGE","url":"https://github.com/flightphp/core"},{"type":"WEB","url":"https://github.com/flightphp/core/releases/tag/v3.18.1"}],"affected":[{"package":{"name":"flightphp/core","ecosystem":"Packagist","purl":"pkg:composer/flightphp/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.18.1"}]}],"versions":["v1.0","v1.1","v1.1.10","v1.1.5","v1.2","v1.2.13","v1.2.14","v1.2.15","v1.2.17","v1.2.18","v1.2.19","v1.2.20","v1.2.21","v1.2.22","v1.3.0","v1.3.1","v1.3.2","v1.3.3","v1.3.4","v1.3.5","v1.3.7","v1.3.8","v1.3.9","v2.0.0","v2.0.1","v3.0.0","v3.0.1","v3.0.2","v3.1.0","v3.1.1","v3.10.0","v3.10.1","v3.11.0","v3.11.1","v3.12.0","v3.13.0","v3.13.1","v3.14.0","v3.15.0","v3.15.1","v3.15.2","v3.15.3","v3.16.0","v3.16.1","v3.17.0","v3.17.1","v3.17.2","v3.17.3","v3.17.4","v3.18.0","v3.2.0","v3.3.0","v3.4.0","v3.4.1","v3.4.2","v3.5.0","v3.5.2","v3.5.3","v3.6.0","v3.6.1","v3.6.2","v3.7.0","v3.7.1","v3.7.2","v3.8.0","v3.8.1","v3.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vxrr-w42w-w76g/GHSA-vxrr-w42w-w76g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}