PT-2025-11347 · Php+11 · Php+11

Jakub Zelenka

·

Published

2025-01-01

·

Updated

2026-03-06

·

CVE-2025-1861

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Report

Name of the Vulnerable Software and Affected Versions
PHP versions 8.1.0 through 8.1.31 PHP versions 8.2.0 through 8.2.27 PHP versions 8.3.0 through 8.3.18 PHP versions 8.4.0 through 8.4.4 PHP 7.4 (Debian)
Description
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A vulnerability exists in PHP due to a limited location buffer size when parsing HTTP redirects. This can lead to incorrect URL truncation and redirection to a wrong location.
Recommendations
PHP versions 8.1.0 through 8.1.31: Upgrade to version 8.1.32 or later. PHP versions 8.2.0 through 8.2.27: Upgrade to version 8.2.28 or later. PHP versions 8.3.0 through 8.3.18: Upgrade to version 8.3.19 or later. PHP versions 8.4.0 through 8.4.4: Upgrade to version 8.4.5 or later. PHP 7.4 (Debian): Upgrade to a newer version.

Fix

RCE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15687
ALSA-2025:4263
ALSA-2025:7418
ALSA-2025:7431
ALSA-2025:7432
ALSA-2025:7489
ALSA-2026:2470
ALT-PU-2025-4202
ALT-PU-2025-4313
ALT-PU-2025-4317
ALT-PU-2025-4377
ALT-PU-2025-4406
ALT-PU-2025-4565
AZL-59306
AZL-59330
BDU:2025-02835
BIT-LIBPHP-2025-1861
BIT-PHP-2025-1861
BIT-PHP-MIN-2025-1861
CESA-2025_15687
CVE-2025-1861
DLA-4088-1
DSA-5878-1
GHSA-52JP-HRPF-2JFF
INFSA-2025_15687
INFSA-2025_4263
INFSA-2025_7418
INFSA-2025_7431
INFSA-2025_7432
MGASA-2025-0100
OESA-2025-1302
OESA-2025-1303
OESA-2025-1304
OESA-2025-1305
OESA-2025-1306
OPENSUSE-SU-2025:14895-1
OPENSUSE-SU-2025_0994-1
OPENSUSE-SU-2025_1012-1
OPENSUSE-SU-2025_1025-1
RHSA-2025:4263
RHSA-2025:7418
RHSA-2025:7431
RHSA-2025:7432
RHSA-2025:7489
RHSA-2025_15687
RHSA-2025_4263
RHSA-2025_7418
RHSA-2025_7431
RHSA-2025_7432
RHSA-2026:2470
SUSE-SU-2025:0994-1
SUSE-SU-2025:1012-1
SUSE-SU-2025:1025-1
SUSE-SU-2025:1026-1
USN-7400-1
USN-7645-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu