CVE-2025-1734 Information

Description

In PHP from 8.1. before 8.1.32 from 8.2. before 8.2.28 from 8.3. before 8.3.19 from 8.4. before 8.4.5 when receiving headers from HTTP server the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.

Reference

https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44

Share on: