CVE-2025-1217

Updated: 2025-11-10 02:32:43.021585

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x LOW 3.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 php 7.3 3.1 LOW Released CLSA-2026:1771245338 2026-02-16 14:41:32
Alpine Linux 3.22 php 7.4 3.1 LOW Released CLSA-2026:1769188145 2026-01-23 21:45:47
Alpine Linux 3.22 php 8.1 3.1 LOW Already Fixed 2026-02-18 11:30:44
Debian 10 php 8.0 3.1 LOW Already Fixed 2025-06-12 00:45:02
Debian 10 php 5.6 3.1 LOW Already Fixed 2025-06-12 00:45:04
Debian 10 php 7.3 3.1 LOW Already Fixed 2025-06-12 00:45:02
Debian 10 php 8.2 3.1 LOW Already Fixed 2025-06-05 02:27:50
Debian 10 php 8.1 3.1 LOW Already Fixed 2025-06-05 02:27:50
Debian 10 php 7.0 3.1 LOW Already Fixed 2025-06-12 00:45:02
Debian 10 php 7.1 3.1 LOW Already Fixed 2025-06-12 00:45:02
Total: 140