In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
2025-03-30T06:15:14.803
2025-07-02T20:14:40.817
Analyzed
CVSSv3.1: 7.3 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 8.1.32 | Yes |
Application | php | php | < 8.2.28 | Yes |
Application | php | php | < 8.3.19 | Yes |
Application | php | php | < 8.4.5 | Yes |
Application | netapp | ontap | 9 | Yes |