In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
2025-03-30T06:15:14.603
2025-07-02T20:13:31.447
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 8.1.32 | Yes |
Application | php | php | < 8.2.28 | Yes |
Application | php | php | < 8.3.19 | Yes |
Application | php | php | < 8.4.5 | Yes |
Application | netapp | ontap | 9 | Yes |