CVE-2025-1736

Updated: 2025-11-10 02:43:26.067207

Description:

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 6 ELS php 5.3.3 7.3 HIGH Ignored 2025-09-20 15:03:49 We have reasoned not to port this fix as the changes are too intrusive and may bring new and seriou...
Oracle Linux 7 ELS php 5.4.16 7.3 HIGH Released CLSA-2025:1756323917 2025-08-28 01:09:39
RHEL 7 ELS php 5.4.16 7.3 HIGH Released CLSA-2025:1756323821 2025-08-28 01:05:36
TuxCare 9.6 ESU php 8.0.30 7.3 HIGH Already Fixed 2025-11-27 09:30:39
Ubuntu 16.04 ELS php 7.0.33 7.3 HIGH Released CLSA-2025:1757016160 2025-09-04 21:54:54
Ubuntu 18.04 ELS php 7.2.24-0 7.3 HIGH Released CLSA-2025:1757014652 2025-09-04 21:54:53
Ubuntu 20.04 ELS php 7.4.3 7.3 HIGH Released CLSA-2025:1758289909 2025-09-23 19:33:46
Total: 17