CVE-2025-1734

Updated: 2025-11-10 02:43:17.122234

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 6 ELS php 5.3.3 5.3 MEDIUM Released CLSA-2025:1756483693 2025-08-29 20:01:13
Oracle Linux 7 ELS php 5.4.16 5.3 MEDIUM Released CLSA-2025:1747690840 2025-05-21 01:44:55
RHEL 7 ELS php 5.4.16 5.3 MEDIUM Ignored 2025-07-08 04:28:46 Ignored due to low severity
TuxCare 9.6 ESU php 8.0.30 5.3 MEDIUM Already Fixed 2025-12-23 00:40:14
Ubuntu 16.04 ELS php 7.0.33 5.3 MEDIUM Released CLSA-2025:1757016160 2025-09-04 21:54:38
Ubuntu 18.04 ELS php 7.2.24-0 5.3 MEDIUM Released CLSA-2025:1757014652 2025-09-04 21:54:37
Ubuntu 20.04 ELS php 7.4.3 5.3 MEDIUM Already Fixed 2025-04-18 03:57:09
Total: 17