Количество 21
Количество 21
GHSA-pcmh-g36c-qc44
Streams HTTP wrapper does not fail for headers with invalid name and no colon
CVE-2025-1734
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
CVE-2025-1734
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
CVE-2025-1734
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
CVE-2025-1734
Streams HTTP wrapper does not fail for headers with invalid name and no colon
CVE-2025-1734
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...
BDU:2025-02827
Уязвимость интерпретатора языка программирования PHP, связанная с недостатками обработки заголовков HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
ELSA-2025-7431
ELSA-2025-7431: php security update (MODERATE)
SUSE-SU-2025:1026-1
Security update for php7
SUSE-SU-2025:1025-1
Security update for php7
SUSE-SU-2025:1012-1
Security update for php8
SUSE-SU-2025:0994-1
Security update for php8
RLSA-2025:7489
Important: php security update
ELSA-2025-7489
ELSA-2025-7489: php security update (IMPORTANT)
ELSA-2025-7418
ELSA-2025-7418: php:8.3 security update (IMPORTANT)
ELSA-2025-7432
ELSA-2025-7432: php:8.2 security update (MODERATE)
ELSA-2025-4263
ELSA-2025-4263: php:8.1 security update (MODERATE)
ELSA-2025-15687
ELSA-2025-15687: php:8.2 security update (MODERATE)
ROS-20250430-12
Множественные уязвимости php 8.3
ROS-20250430-11
Множественные уязвимости php 8.2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pcmh-g36c-qc44 Streams HTTP wrapper does not fail for headers with invalid name and no colon | 0% Низкий | 8 месяцев назад | ||
CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers. | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers. | CVSS3: 3.7 | 0% Низкий | 7 месяцев назад | |
CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers. | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-1734 Streams HTTP wrapper does not fail for headers with invalid name and no colon | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ... | CVSS3: 5.3 | 0% Низкий | 7 месяцев назад | |
BDU:2025-02827 Уязвимость интерпретатора языка программирования PHP, связанная с недостатками обработки заголовков HTTP-запросов, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling) | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
ELSA-2025-7431 ELSA-2025-7431: php security update (MODERATE) | 6 месяцев назад | |||
SUSE-SU-2025:1026-1 Security update for php7 | 7 месяцев назад | |||
SUSE-SU-2025:1025-1 Security update for php7 | 7 месяцев назад | |||
SUSE-SU-2025:1012-1 Security update for php8 | 7 месяцев назад | |||
SUSE-SU-2025:0994-1 Security update for php8 | 7 месяцев назад | |||
RLSA-2025:7489 Important: php security update | около 1 месяца назад | |||
ELSA-2025-7489 ELSA-2025-7489: php security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2025-7418 ELSA-2025-7418: php:8.3 security update (IMPORTANT) | 6 месяцев назад | |||
ELSA-2025-7432 ELSA-2025-7432: php:8.2 security update (MODERATE) | 6 месяцев назад | |||
ELSA-2025-4263 ELSA-2025-4263: php:8.1 security update (MODERATE) | 6 месяцев назад | |||
ELSA-2025-15687 ELSA-2025-15687: php:8.2 security update (MODERATE) | около 2 месяцев назад | |||
ROS-20250430-12 Множественные уязвимости php 8.3 | CVSS3: 6.5 | 6 месяцев назад | ||
ROS-20250430-11 Множественные уязвимости php 8.2 | CVSS3: 6.5 | 6 месяцев назад |
Уязвимостей на страницу