CVE-2025-1736

Updated: 2025-11-10 02:43:26.067207

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 7.3 HIGH Released CLSA-2025:1753981912 2025-08-01 01:02:35
Alpine Linux 3.18 ELS php 8.2.16 7.3 HIGH Released CLSA-2025:1766049917 2025-12-19 05:00:01
CentOS 6 ELS php 5.3.3 7.3 HIGH Ignored 2025-09-20 15:03:46 We have reasoned not to port this fix as the changes are too intrusive and may bring new and seriou...
CentOS 7 ELS php 5.4.16 7.3 HIGH Released CLSA-2025:1756322698 2025-09-05 19:32:13
CentOS 8.4 ELS php 7.4.6 7.3 HIGH Released CLSA-2025:1744782851 2025-04-17 03:56:47
CentOS 8.5 ELS php 7.4.19 7.3 HIGH Released CLSA-2025:1744875533 2025-04-18 03:57:12
CentOS Stream 8 ELS php 7.2.24 7.3 HIGH Released CLSA-2025:1746654810 2025-05-10 05:05:33
CloudLinux 6 ELS php 5.3.3 7.3 HIGH Ignored 2025-08-29 15:19:26
CloudLinux 7 ELS php 5.4.16 7.3 HIGH Released CLSA-2025:1756322954 2025-09-10 14:16:32
Debian 10 ELS php 7.3 7.3 HIGH Released CLSA-2025:1761082274 2025-10-22 09:31:58
Total: 17