PT-2025-11344 · Php+11 · Php+11

Tim Düsterhus

·

Published

2025-01-01

·

Updated

2026-02-10

·

CVE-2025-1219

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PHP versions 8.1.* through 8.1.31 PHP versions 8.2.* through 8.2.27 PHP versions 8.3.* through 8.3.18 PHP versions 8.4.* through 8.4.4
Description The issue is related to the use of the wrong content-type header to determine the charset when a requested resource performs a redirect, potentially causing the resulting document to be parsed incorrectly or bypass validations. This can occur when requesting an HTTP resource using the DOM or SimpleXML extensions in PHP. The vulnerability may allow a remote attacker to redirect a user to an arbitrary URL.
Recommendations Update PHP to version 8.1.32 or later for versions 8.1.* Update PHP to version 8.2.28 or later for versions 8.2.* Update PHP to version 8.3.19 or later for versions 8.3.* Update PHP to version 8.4.5 or later for versions 8.4.*

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

ALSA-2025:15687
ALSA-2025:4263
ALSA-2025:7418
ALSA-2025:7431
ALSA-2025:7432
ALSA-2025:7489
ALSA-2026:2470
ALT-PU-2025-4202
ALT-PU-2025-4313
ALT-PU-2025-4317
ALT-PU-2025-4377
ALT-PU-2025-4406
ALT-PU-2025-4565
AZL-59300
AZL-59316
BDU:2025-02829
BIT-LIBPHP-2025-1219
BIT-PHP-2025-1219
BIT-PHP-MIN-2025-1219
CESA-2025_15687
CVE-2025-1219
DLA-4088-1
DSA-5878-1
GHSA-P3X9-6H7P-CGFC
INFSA-2025_15687
INFSA-2025_4263
INFSA-2025_7418
INFSA-2025_7431
INFSA-2025_7432
MGASA-2025-0100
OESA-2025-1302
OESA-2025-1303
OESA-2025-1304
OESA-2025-1305
OESA-2025-1306
OPENSUSE-SU-2025:14895-1
OPENSUSE-SU-2025_0994-1
OPENSUSE-SU-2025_1012-1
OPENSUSE-SU-2025_1025-1
RHSA-2025:4263
RHSA-2025:7418
RHSA-2025:7431
RHSA-2025:7432
RHSA-2025:7489
RHSA-2025_15687
RHSA-2025_4263
RHSA-2025_7418
RHSA-2025_7431
RHSA-2025_7432
RHSA-2026:2470
SUSE-SU-2025:0994-1
SUSE-SU-2025:1012-1
SUSE-SU-2025:1025-1
SUSE-SU-2025:1026-1
USN-7400-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu