Skip to main content
EPSS 0.6%top 55%

Php: Header parser of http stream wrapper does not handle folded headers (CVE-2025-1217)

0
Medium
Published: 04/14/2025 (04/14/2025, 11:39:16 UTC)
Source: GCVE Database
Product: php

Description

A vulnerability in PHP's HTTP stream wrapper header parser affects versions prior to 8.1.32, 8.2.28, 8.3.19, and 8.4.5. The parser incorrectly handles folded HTTP headers, which can lead to misinterpretation of HTTP responses, including incorrect headers and MIME types. This issue has been rated as moderate severity by Red Hat Product Security. A patch is available to address this vulnerability.

Affected software

Affected versions
<8.1.32>=8.2.0 <8.2.28>=8.3.0 <8.3.19>=8.4.0 <8.4.5

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 15:17:18 UTC

Technical Analysis

CVE-2025-1217 describes a vulnerability in PHP's HTTP stream wrapper where folded HTTP headers are parsed incorrectly. This flaw exists in PHP versions 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5. The incorrect parsing may cause the HTTP response to be misinterpreted, potentially leading to the use of incorrect headers or MIME types. The issue is tracked and patched by Red Hat in their advisory RHSA-2025:7431, which also addresses related PHP stream wrapper vulnerabilities. No CVSS score is provided, but the vendor rates the impact as moderate.

Potential Impact

Misinterpretation of HTTP responses due to incorrect parsing of folded headers can cause applications relying on PHP's HTTP stream wrapper to use incorrect headers or MIME types. This may affect application behavior or security controls that depend on accurate HTTP header processing. No known exploits are reported in the wild.

Mitigation Recommendations

A security update fixing this vulnerability is available and should be applied. Red Hat has released patched PHP packages in Red Hat Enterprise Linux 9 and related variants as detailed in advisory RHSA-2025:7431. Users should upgrade to PHP versions 8.1.32 or later, 8.2.28 or later, 8.3.19 or later, or 8.4.5 or later to remediate this issue. Refer to the vendor advisory for update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:7431
Cve Count
5
Additional Cves
["CVE-2025-1219","CVE-2025-1734","CVE-2025-1736","CVE-2025-1861"]

Threat ID: 6a4049e927e9c7971983592e

Added to database: 06/27/2026, 22:08:41 UTC

Last enriched: 09/08/2026, 15:17:18 UTC

Last updated: 09/10/2026, 19:24:55 UTC

Views: 45

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses