VYPR
Unrated severityNVD Advisory· Published Mar 30, 2025· Updated Nov 3, 2025

Stream HTTP wrapper header check might omit basic auth header

CVE-2025-1736

Description

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

150

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.