PT-2025-41579 · Http.Jl · Http.Jl
Chen T
·
Published
2025-10-10
·
Updated
2025-10-14
·
CVE-2025-61689
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
HTTP.jl versions prior to 1.10.19
Description
HTTP.jl, an HTTP client and server for the Julia programming language, did not properly validate header names and values, creating a risk of header injection and response splitting. This could lead to several security issues, including cache poisoning, cross-site scripting (XSS), and session fixation. The issue stems from a lack of validation for illegal characters in header data. The vulnerable component is the handling of HTTP headers.
Recommendations
Update HTTP.jl to version 1.10.19 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http.Jl