Description
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
Problem types
CWE-20 Improper Input Validation
Product status
8.1.* (semver) before 8.1.32
8.2.* (semver) before 8.2.28
8.3.* (semver) before 8.3.19
8.4.* (semver) before 8.4.5
Credits
Jakub Zelenka
References
security.netapp.com/advisory/ntap-20250523-0009/
lists.debian.org/debian-lts-announce/2025/03/msg00014.html
github.com/...hp-src/security/advisories/GHSA-pcmh-g36c-qc44
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.