Site icon API Security Blog

Linux Distros Unpatched Vulnerability : CVE-2025-1861

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. In PHP from 8.1. before 8.1.32, from 8.2. before 8.2.28, from 8.3. before 8.3.19, from 8.4. before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location. (CVE-2025-1861) Note that Nessus relies on the presence of the package as reported by the vendor. File data…Read More

Exit mobile version