In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
2025-03-30T06:15:14.603
2025-11-03T21:18:52.790
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | php | php | < 8.1.32 | Yes |
| Application | php | php | < 8.2.28 | Yes |
| Application | php | php | < 8.3.19 | Yes |
| Application | php | php | < 8.4.5 | Yes |
| Application | netapp | ontap | 9 | Yes |