CVE-2025-1861·PHP vulnerability
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
- Severity
- critical
- Software
- PHP
- Fixed in
- 8.4.5
- Published
- 2025-03-30
Affected versions
From: 8.4.0
Until: 8.4.5
Fixed in: 8.4.5
How to fix this CVE
Update PHP to version 8.4.5 or later to resolve this HTTP redirect handling vulnerability. The issue stems from PHP's HTTP client limiting redirect location headers to 1024 bytes instead of the RFC9110-recommended 8000 bytes, which can cause redirect URLs to be truncated and users redirected to unintended destinations. Applying this patch ensures proper RFC compliance and eliminates the risk of URL manipulation through malformed redirect responses.
sudo dnf update phpDefensia detects this vulnerability
How to check if you are affected
- Run `php -v` to check the currently installed PHP version and verify if it is between 8.4.0 and 8.4.4
- Check if PHP's HTTP stream wrapper is being used for external URL requests by grep for 'stream_get_contents', 'fopen', or 'file_get_contents' with HTTP/HTTPS URLs in application code
- Review web server access and error logs for HTTP 3xx redirect responses with truncated Location headers exceeding 1024 bytes
- After patching, re-run `php -v` to confirm PHP version is now 8.4.5 or later and restart the PHP-FPM service with `sudo systemctl restart php-fpm`
FAQ
What is CVE-2025-1861?
CVE-2025-1861 is a critical vulnerability in PHP's HTTP redirect handler that truncates Location header values at 1024 bytes instead of the RFC9110-recommended 8000 bytes, potentially redirecting users to incorrect or malicious URLs when following HTTP redirects in application code.
Is CVE-2025-1861 being actively exploited?
No, CVE-2025-1861 is not currently listed in the CISA KEV catalog and no public exploits are available, though the critical CVSS score warrants immediate patching.
What versions of PHP are affected by CVE-2025-1861?
PHP versions 8.1.0 through 8.1.31, 8.2.0 through 8.2.27, 8.3.0 through 8.3.18, and 8.4.0 through 8.4.4 are affected. Version 8.4.5 and later contain the fix.
How do I check if my server is vulnerable to CVE-2025-1861?
Run `php -v` and cross-reference the output against the affected ranges above. If your version falls within any of these ranges, your server is vulnerable and requires immediate update.
Does Defensia detect CVE-2025-1861?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP is installed on a monitored server, CVE-2025-1861 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-1861. Free for 1 server.
Get started free