HTTP Response Splitting Affecting nyholm/psr7 package, versions <1.6.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-NYHOLMPSR7-5457865
  • published23 Apr 2023
  • disclosed21 Apr 2023
  • creditdevanych

Introduced: 21 Apr 2023

CVE NOT AVAILABLE CWE-113  (opens in a new tab)

How to fix?

Upgrade nyholm/psr7 to version 1.6.1 or higher.

Overview

nyholm/psr7 is a PHP7 implementation of PSR-7.

Affected versions of this package are vulnerable to HTTP Response Splitting due to improper header parsing, such that an attacker could sneak in a newline \n into both the header names and values.

CVSS Base Scores

version 3.1