CVE-2025-1861

CRITICAL
Published Mar 30, 2025 Modified Nov 3, 2025 CWE-131

Description

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-131 CWE-131

Affected Products

Vendor Product
php php
php php
php php
php php
netapp ontap

References

Frequently Asked Questions

What is CVE-2025-1861? +
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location. It has a CVSS v3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2025-1861? +
CVE-2025-1861 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2025-1861? +
CVE-2025-1861 affects products from netapp, php, specifically: ontap, php. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-1861? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-1861 — free, no signup required.

Start Free Scan