CVE-2025-1734

Updated: 2025-11-10 02:43:17.122234

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 5.3 MEDIUM Released CLSA-2025:1753981912 2025-08-01 01:02:34
Alpine Linux 3.18 ELS php 8.2.16 5.3 MEDIUM Ignored 2025-09-10 13:44:40 Ignored due to low severity
CentOS 6 ELS php 5.3.3 5.3 MEDIUM Released CLSA-2025:1756483990 2025-09-10 14:16:17
CentOS 7 ELS php 5.4.16 5.3 MEDIUM Released CLSA-2025:1747740986 2025-06-02 16:08:48
CentOS 8.4 ELS php 7.4.6 5.3 MEDIUM Released CLSA-2025:1744723009 2025-04-16 04:34:27
CentOS 8.5 ELS php 7.4.19 5.3 MEDIUM Released CLSA-2025:1744723558 2025-04-16 04:34:28
CentOS Stream 8 ELS php 7.2.24 5.3 MEDIUM Released CLSA-2025:1746654810 2025-05-10 05:05:27
CloudLinux 6 ELS php 5.3.3 5.3 MEDIUM Ignored 2025-08-29 15:19:14
CloudLinux 7 ELS php 5.4.16 5.3 MEDIUM Released CLSA-2025:1747742261 2025-06-02 16:08:47
Debian 10 ELS php 7.3 5.3 MEDIUM Ignored 2025-10-11 00:17:29 Ignored due to low severity
Total: 17