Updated: 2025-11-10 02:43:26.067207
Description:
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | HIGH | 7.3 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | php | 8.0.30 | 7.3 | HIGH | Released | CLSA-2025:1753981912 | 2025-08-01 01:02:35 | |
| Alpine Linux 3.18 ELS | php | 8.2.16 | 7.3 | HIGH | Released | CLSA-2025:1766049917 | 2025-12-19 05:00:01 | |
| CentOS 6 ELS | php | 5.3.3 | 7.3 | HIGH | Ignored | 2025-09-20 15:03:46 | We have reasoned not to port this fix as the changes are too intrusive and may bring new and seriou... | |
| CentOS 7 ELS | php | 5.4.16 | 7.3 | HIGH | Released | CLSA-2025:1756322698 | 2025-09-05 19:32:13 | |
| CentOS 8.4 ELS | php | 7.4.6 | 7.3 | HIGH | Released | CLSA-2025:1744782851 | 2025-04-17 03:56:47 | |
| CentOS 8.5 ELS | php | 7.4.19 | 7.3 | HIGH | Released | CLSA-2025:1744875533 | 2025-04-18 03:57:12 | |
| CentOS Stream 8 ELS | php | 7.2.24 | 7.3 | HIGH | Released | CLSA-2025:1746654810 | 2025-05-10 05:05:33 | |
| CloudLinux 6 ELS | php | 5.3.3 | 7.3 | HIGH | Ignored | 2025-08-29 15:19:26 | ||
| CloudLinux 7 ELS | php | 5.4.16 | 7.3 | HIGH | Released | CLSA-2025:1756322954 | 2025-09-10 14:16:32 | |
| Debian 10 ELS | php | 7.3 | 7.3 | HIGH | Released | CLSA-2025:1761082274 | 2025-10-22 09:31:58 |