PT-2025-41579 · Http.Jl · Http.Jl

Chen T

·

Published

2025-10-10

·

Updated

2025-10-14

·

CVE-2025-61689

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions HTTP.jl versions prior to 1.10.19
Description HTTP.jl, an HTTP client and server for the Julia programming language, did not properly validate header names and values, creating a risk of header injection and response splitting. This could lead to several security issues, including cache poisoning, cross-site scripting (XSS), and session fixation. The issue stems from a lack of validation for illegal characters in header data. The vulnerable component is the handling of HTTP headers.
Recommendations Update HTTP.jl to version 1.10.19 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-61689
GHSA-H3X8-PPWJ-6VCJ
JLSEC-2025-40

Affected Products

Http.Jl