Threats Tagged 'cve-2025-1861'
View all threats tagged with 'cve-2025-1861'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-1861'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities have been identified and addressed in PHP as packaged by Red Hat Enterprise Linux 10. These include issues in the HTTP stream wrapper related to header parsing, authentication header omission, invalid header handling, content-type header misuse on redirects, and redirect location truncation. Additionally, a use-after-free vulnerability exists in the PHP request shutdown process. Red Hat has released updates to fix these issues in their PHP packages for various architectures and support levels. Join the discussion | GCVE Database | 05/13/2025, 17:18:22 UTC Added: 06/27/2026, 22:08:41 UTC |
0 A vulnerability in PHP's HTTP stream wrapper header parser affects versions prior to 8.1.32, 8.2.28, 8.3.19, and 8.4.5. The parser incorrectly handles folded HTTP headers, which can lead to misinterpretation of HTTP responses, including incorrect headers and MIME types. This issue has been rated as moderate severity by Red Hat Product Security. A patch is available to address this vulnerability. Join the discussion | GCVE Database | 04/14/2025, 11:39:16 UTC Added: 06/27/2026, 22:08:41 UTC |
A use-after-free vulnerability exists in PHP versions 8.3 prior to 8.3.19 and 8.4 prior to 8.4.5 involving reference counting during php_request_shutdown. This flaw can be triggered by specific code sequences using the __set handler or the ??= operator combined with exceptions. Exploitation requires control over memory layout, potentially allowing remote code execution. Red Hat has issued security updates addressing this vulnerability. Join the discussion | GCVE Database | 04/14/2025, 11:38:04 UTC Added: 06/27/2026, 22:08:41 UTC |
0 A heap buffer over-read vulnerability exists in the mysqlnd extension of PHP, affecting multiple PHP versions prior to specific fixed releases. A hostile MySQL server can exploit this flaw to cause the PHP client to leak partial heap contents, potentially disclosing data from other SQL requests or other users on the same server. This vulnerability has been assigned CVE-2024-8929 and is rated as having moderate security impact. Official patches are available and have been released by vendors including Red Hat. Join the discussion | GCVE Database | 11/27/2024, 19:18:36 UTC Added: 06/06/2026, 21:13:28 UTC |
Showing 1 to 4 of 4 results