PT-2025-11343 · Php+11 · Php+11

Tim Düsterhus

·

Published

2025-01-01

·

Updated

2026-02-10

·

CVE-2025-1217

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/AU:Y/R:A
Name of the Vulnerable Software and Affected Versions PHP versions 8.1.* through 8.1.31 PHP versions 8.2.* through 8.2.27 PHP versions 8.3.* through 8.3.18 PHP versions 8.4.* through 8.4.4
Description The issue is related to the incorrect parsing of folded headers in HTTP responses by the http request module in PHP. This may lead to misinterpreting the response and using incorrect headers, MIME types, etc. The vulnerability can be exploited by a remote attacker to send hidden HTTP requests.
Recommendations For PHP versions 8.1.* through 8.1.31, update to version 8.1.32 or later. For PHP versions 8.2.* through 8.2.27, update to version 8.2.28 or later. For PHP versions 8.3.* through 8.3.18, update to version 8.3.19 or later. For PHP versions 8.4.* through 8.4.4, update to version 8.4.5 or later. As a temporary workaround, consider restricting access to the http stream wrapper until a patch is available.

Exploit

Fix

HTTP Request/Response Smuggling

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15687
ALSA-2025:4263
ALSA-2025:7418
ALSA-2025:7431
ALSA-2025:7432
ALSA-2025:7489
ALSA-2026:2470
ALT-PU-2025-4202
ALT-PU-2025-4313
ALT-PU-2025-4317
ALT-PU-2025-4377
ALT-PU-2025-4406
ALT-PU-2025-4565
AZL-59291
AZL-59294
BDU:2025-02828
BIT-LIBPHP-2025-1217
BIT-PHP-2025-1217
BIT-PHP-MIN-2025-1217
CESA-2025_15687
CVE-2025-1217
DLA-4088-1
DSA-5878-1
GHSA-V8XR-GPVJ-CX9G
INFSA-2025_15687
INFSA-2025_4263
INFSA-2025_7418
INFSA-2025_7431
INFSA-2025_7432
MGASA-2025-0100
OESA-2025-1302
OESA-2025-1303
OESA-2025-1304
OESA-2025-1305
OESA-2025-1306
OPENSUSE-SU-2025:14895-1
OPENSUSE-SU-2025_0994-1
OPENSUSE-SU-2025_1012-1
OPENSUSE-SU-2025_1025-1
RHSA-2025:4263
RHSA-2025:7418
RHSA-2025:7431
RHSA-2025:7432
RHSA-2025:7489
RHSA-2025_15687
RHSA-2025_4263
RHSA-2025_7418
RHSA-2025_7431
RHSA-2025_7432
RHSA-2026:2470
SUSE-SU-2025:0994-1
SUSE-SU-2025:1012-1
SUSE-SU-2025:1025-1
SUSE-SU-2025:1026-1
USN-7400-1
USN-7645-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu