CVE-2025-1217

Updated: 2025-11-10 02:32:43.021585

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x LOW 3.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 3.1 LOW Released CLSA-2025:1753981912 2025-08-01 01:02:33
Alpine Linux 3.18 ELS php 8.2.16 3.1 LOW Ignored 2025-09-08 14:51:42 Ignored due to low severity
CentOS 6 ELS php 5.3.3 3.1 LOW Released CLSA-2025:1756483990 2025-09-10 14:16:10
CentOS 7 ELS php 5.4.16 3.1 LOW Released CLSA-2025:1747740986 2025-06-02 16:08:42
CentOS 8.4 ELS php 7.4.6 3.1 LOW Released CLSA-2025:1744723009 2025-04-16 04:34:22
CentOS 8.5 ELS php 7.4.19 3.1 LOW Released CLSA-2025:1744723558 2025-04-16 04:34:23
CentOS Stream 8 ELS php 7.2.24 3.1 LOW Released CLSA-2025:1746654810 2025-05-10 05:05:24
CloudLinux 6 ELS php 5.3.3 3.1 LOW Ignored 2025-08-29 15:19:08
CloudLinux 7 ELS php 5.4.16 3.1 LOW Released CLSA-2025:1747742261 2025-06-02 16:08:41
Debian 10 ELS php 7.3 3.1 LOW Ignored 2025-10-11 00:20:53 Ignored due to low severity
Total: 17