Innovate faster and cut risk with PHP experts from Zend Services.
Explore Services
See How Zend Helps Leading Hosting Providers Keep Their Managed Sites on Secure PHP
Read More
Learn PHP from PHP experts with free, on-demand, and instructor led courses.
Explore Training
Submit support requests and browse self-service resources.
Explore Support
Streams HTTP wrapper does not fail for headers without colon
In PHP versions 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5, a vulnerability, which was classified as problematic, has been found. This issue affects some unknown functionality of the component Streams HTTP Wrapper. Headers missing a colon (":") are treated as valid, even though they are not, confusing applications into accepting invalid headers.
:
If you are using the PHP streams HTTP wrapper to make HTTP requests, we recommend using another HTTP request extension, such as cURL, if you are unable to update.
Otherwise, we recommend upgrading to a known patched version of PHP.
Direct link to CVE-2025-1734 >
< View all CVEs