In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Apr 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Mon, 31 Mar 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 30 Mar 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location. | |
Title | Stream HTTP wrapper truncates redirect location to 1024 bytes | |
Weaknesses | CWE-131 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-03-31T12:56:00.966Z
Reserved: 2025-03-03T04:47:51.192Z
Link: CVE-2025-1861

Updated: 2025-03-31T12:55:56.941Z

Status : Awaiting Analysis
Published: 2025-03-30T06:15:14.957
Modified: 2025-04-01T20:26:30.593
Link: CVE-2025-1861
