Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-1736

Опубликовано: 30 мар. 2025
Источник: debian
EPSS Низкий

Описание

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.4fixed8.4.5-1package
php8.2unfixedpackage
php7.4removedpackage

Примечания

  • https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528

  • Fixed by: https://github.com/php/php-src/commit/41d49abbd99dab06cdae4834db664435f8177174 (php-8.1.32)

EPSS

Процентиль: 38%
0.00158
Низкий

Связанные уязвимости

ubuntu
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 3.7
redhat
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

nvd
3 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

msrc
3 месяца назад

Описание отсутствует

github
3 месяца назад

Stream HTTP wrapper header check might omit basic auth header

EPSS

Процентиль: 38%
0.00158
Низкий