PT-2025-11346 · Php+11 · Php+11

Jakub Zelenka

·

Published

2025-01-01

·

Updated

2026-02-10

·

CVE-2025-1736

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PHP versions 8.1.* through 8.1.31 PHP versions 8.2.* through 8.2.27 PHP versions 8.3.* through 8.3.18 PHP versions 8.4.* through 8.4.4
Description The issue is related to the insufficient validation of end-of-line characters in user-supplied headers, which may prevent certain headers from being sent or lead to certain headers being misinterpreted. This can potentially impact the result and lead to denial of service or unexpected issues. The check has header() function is specifically mentioned as being related to this issue, where the lack of verification of r could lead to misbehavior if only is used in the header value.
Recommendations Update to PHP version 8.1.32 or later for versions 8.1.* Update to PHP version 8.2.28 or later for versions 8.2.* Update to PHP version 8.3.19 or later for versions 8.3.* Update to PHP version 8.4.5 or later for versions 8.4.* As a temporary workaround, consider disabling the check has header() function until a patch is available. Restrict access to user-supplied headers to minimize the risk of exploitation. Avoid using the Cookie header with user-input values until the issue is resolved.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15687
ALSA-2025:4263
ALSA-2025:7418
ALSA-2025:7431
ALSA-2025:7432
ALSA-2025:7489
ALSA-2026:2470
ALT-PU-2025-4202
ALT-PU-2025-4313
ALT-PU-2025-4317
ALT-PU-2025-4377
ALT-PU-2025-4406
ALT-PU-2025-4565
AZL-59303
AZL-59331
BDU:2025-02834
BIT-LIBPHP-2025-1736
BIT-PHP-2025-1736
BIT-PHP-MIN-2025-1736
CESA-2025_15687
CVE-2025-1736
DLA-4088-1
DSA-5878-1
GHSA-HGF5-96FM-V528
INFSA-2025_15687
INFSA-2025_4263
INFSA-2025_7418
INFSA-2025_7431
INFSA-2025_7432
MGASA-2025-0100
OESA-2025-1302
OESA-2025-1303
OESA-2025-1304
OESA-2025-1305
OESA-2025-1306
OPENSUSE-SU-2025:14895-1
OPENSUSE-SU-2025_0994-1
OPENSUSE-SU-2025_1012-1
OPENSUSE-SU-2025_1025-1
RHSA-2025:4263
RHSA-2025:7418
RHSA-2025:7431
RHSA-2025:7432
RHSA-2025:7489
RHSA-2025_15687
RHSA-2025_4263
RHSA-2025_7418
RHSA-2025_7431
RHSA-2025_7432
RHSA-2026:2470
SUSE-SU-2025:0994-1
SUSE-SU-2025:1012-1
SUSE-SU-2025:1025-1
SUSE-SU-2025:1026-1
USN-7400-1
USN-7645-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu