According to https://www.php.net/manual/en/security.cgi-bin.force-redirect.php, the configuration directive cgi.forceredirect prevents anyone from calling PHP directly with a URL like http://host.example/cgi-bin/php/secretdir/script.php. The default value of cgi.forceredirect is 1.
But there is a bug that can cause attackers to bypass restrictions and access php-cgi directly.
Fixed bug (Logs from childrens may be altered). (CVE-2024-9026)
Erroneous parsing of multipart form data