Php: Header parser of http stream wrapper does not handle folded headers (CVE-2025-1217)
A vulnerability in PHP's HTTP stream wrapper header parser affects versions prior to 8.1.32, 8.2.28, 8.3.19, and 8.4.5. The parser incorrectly handles folded HTTP headers, which can lead to misinterpretation of HTTP responses, including incorrect headers and MIME types. This issue has been rated as moderate severity by Red Hat Product Security. A patch is available to address this vulnerability.
AI Analysis
Technical Summary
CVE-2025-1217 describes a vulnerability in PHP's HTTP stream wrapper where folded HTTP headers are parsed incorrectly. This flaw exists in PHP versions 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5. The incorrect parsing may cause the HTTP response to be misinterpreted, potentially leading to the use of incorrect headers or MIME types. The issue is tracked and patched by Red Hat in their advisory RHSA-2025:7431, which also addresses related PHP stream wrapper vulnerabilities. No CVSS score is provided, but the vendor rates the impact as moderate.
Potential Impact
Misinterpretation of HTTP responses due to incorrect parsing of folded headers can cause applications relying on PHP's HTTP stream wrapper to use incorrect headers or MIME types. This may affect application behavior or security controls that depend on accurate HTTP header processing. No known exploits are reported in the wild.
Mitigation Recommendations
A security update fixing this vulnerability is available and should be applied. Red Hat has released patched PHP packages in Red Hat Enterprise Linux 9 and related variants as detailed in advisory RHSA-2025:7431. Users should upgrade to PHP versions 8.1.32 or later, 8.2.28 or later, 8.3.19 or later, or 8.4.5 or later to remediate this issue. Refer to the vendor advisory for update instructions.
Php: Header parser of http stream wrapper does not handle folded headers (CVE-2025-1217)
Description
A vulnerability in PHP's HTTP stream wrapper header parser affects versions prior to 8.1.32, 8.2.28, 8.3.19, and 8.4.5. The parser incorrectly handles folded HTTP headers, which can lead to misinterpretation of HTTP responses, including incorrect headers and MIME types. This issue has been rated as moderate severity by Red Hat Product Security. A patch is available to address this vulnerability.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-1217 describes a vulnerability in PHP's HTTP stream wrapper where folded HTTP headers are parsed incorrectly. This flaw exists in PHP versions 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5. The incorrect parsing may cause the HTTP response to be misinterpreted, potentially leading to the use of incorrect headers or MIME types. The issue is tracked and patched by Red Hat in their advisory RHSA-2025:7431, which also addresses related PHP stream wrapper vulnerabilities. No CVSS score is provided, but the vendor rates the impact as moderate.
Potential Impact
Misinterpretation of HTTP responses due to incorrect parsing of folded headers can cause applications relying on PHP's HTTP stream wrapper to use incorrect headers or MIME types. This may affect application behavior or security controls that depend on accurate HTTP header processing. No known exploits are reported in the wild.
Mitigation Recommendations
A security update fixing this vulnerability is available and should be applied. Red Hat has released patched PHP packages in Red Hat Enterprise Linux 9 and related variants as detailed in advisory RHSA-2025:7431. Users should upgrade to PHP versions 8.1.32 or later, 8.2.28 or later, 8.3.19 or later, or 8.4.5 or later to remediate this issue. Refer to the vendor advisory for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:7431
- Cve Count
- 5
- Additional Cves
- ["CVE-2025-1219","CVE-2025-1734","CVE-2025-1736","CVE-2025-1861"]
Threat ID: 6a4049e927e9c7971983592e
Added to database: 06/27/2026, 22:08:41 UTC
Last enriched: 09/08/2026, 15:17:18 UTC
Last updated: 09/10/2026, 19:24:55 UTC
Views: 45
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.