Php: Null byte termination in hostnames (CVE-2025-1220)
A vulnerability in PHP versions 8.1 before 8.1.33, 8.2 before 8.2.29, 8.3 before 8.3.23, and 8.4 before 8.4.10 allows null byte characters in hostnames passed to functions like fsockopen(). This can cause inconsistent hostname parsing by other functions such as parse_url(), potentially leading to security issues if user code relies on these functions for access control. Red Hat has issued security updates addressing this issue.
AI Analysis
Technical Summary
CVE-2025-1220 is a vulnerability in PHP where certain functions, including fsockopen(), do not validate that hostnames lack null characters. This discrepancy can cause functions like parse_url() to interpret hostnames differently, potentially bypassing access checks implemented in user code. The issue affects PHP versions 8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, and 8.4.* before 8.4.10. Red Hat has released patches for these versions in their Enterprise Linux 8 distributions.
Potential Impact
If exploited, this vulnerability could allow attackers to bypass hostname-based access controls in PHP applications that rely on functions like fsockopen() and parse_url() for validation. This may lead to unauthorized access or other security problems depending on the application logic. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A patch is available and should be applied to affected PHP versions. Red Hat has released updated packages for Red Hat Enterprise Linux 8 that fix this vulnerability. Users should update to PHP versions 8.1.33 or later, 8.2.29 or later, 8.3.23 or later, or 8.4.10 or later as appropriate. Refer to the Red Hat advisory RHSA-2026:1412 for detailed update instructions.
Php: Null byte termination in hostnames (CVE-2025-1220)
Description
A vulnerability in PHP versions 8.1 before 8.1.33, 8.2 before 8.2.29, 8.3 before 8.3.23, and 8.4 before 8.4.10 allows null byte characters in hostnames passed to functions like fsockopen(). This can cause inconsistent hostname parsing by other functions such as parse_url(), potentially leading to security issues if user code relies on these functions for access control. Red Hat has issued security updates addressing this issue.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-1220 is a vulnerability in PHP where certain functions, including fsockopen(), do not validate that hostnames lack null characters. This discrepancy can cause functions like parse_url() to interpret hostnames differently, potentially bypassing access checks implemented in user code. The issue affects PHP versions 8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, and 8.4.* before 8.4.10. Red Hat has released patches for these versions in their Enterprise Linux 8 distributions.
Potential Impact
If exploited, this vulnerability could allow attackers to bypass hostname-based access controls in PHP applications that rely on functions like fsockopen() and parse_url() for validation. This may lead to unauthorized access or other security problems depending on the application logic. No known exploits are reported in the wild at this time.
Mitigation Recommendations
A patch is available and should be applied to affected PHP versions. Red Hat has released updated packages for Red Hat Enterprise Linux 8 that fix this vulnerability. Users should update to PHP versions 8.1.33 or later, 8.2.29 or later, 8.3.23 or later, or 8.4.10 or later as appropriate. Refer to the Red Hat advisory RHSA-2026:1412 for detailed update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:1412
- Cve Count
- 6
- Additional Cves
- ["CVE-2025-1735","CVE-2025-6491","CVE-2025-14177","CVE-2025-14178","CVE-2025-14180"]
Threat ID: 6a248d78e29bf47b50d6577c
Added to database: 06/06/2026, 21:13:28 UTC
Last enriched: 09/08/2026, 15:17:11 UTC
Last updated: 09/10/2026, 19:24:55 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.