CVE-2025-1220

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
13/07/2025
Last modified:
04/11/2025

Description

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.33 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 8.2.0 (including) 8.2.29 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 8.3.0 (including) 8.3.23 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 8.4.0 (including) 8.4.10 (excluding)