Vulnerability CVE-2025-1219: Information

Description

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.

Severity: MEDIUM (6.3)
Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: March 30, 2025
Modified: Nov. 3, 2025
Error type identifier: CWE-1116

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
php8.1sisyphus8.1.32-alt18.1.33-alt1ALT-PU-2025-4307-1377711Fixed
php8.1sisyphus_e2k8.1.32-alt18.1.33-alt1ALT-PU-2025-4716-1-Fixed
php8.1sisyphus_riscv648.1.32-alt18.1.33-alt1ALT-PU-2025-4386-1-Fixed
php8.1sisyphus_loongarch648.1.32-alt18.1.33-alt1ALT-PU-2025-4397-1-Fixed
php8.1p108.1.32-alt18.1.32-alt1ALT-PU-2025-4565-2378690Fixed
php8.1p10_e2k8.1.32-alt18.1.32-alt1ALT-PU-2025-5263-1-Fixed
php8.1c10f28.1.32-alt18.1.33-alt1ALT-PU-2025-4404-2378018Fixed
php8.1p118.1.32-alt18.1.33-alt1ALT-PU-2025-4377-2378017Fixed
php8.2sisyphus8.2.28-alt18.2.29-alt1ALT-PU-2025-4162-1377716Fixed
php8.2sisyphus_e2k8.2.28-alt18.2.29-alt1ALT-PU-2025-5258-1-Fixed
php8.2sisyphus_riscv648.2.28-alt18.2.29-alt1ALT-PU-2025-4249-1-Fixed
php8.2sisyphus_loongarch648.2.28-alt18.2.29-alt1ALT-PU-2025-4278-1-Fixed
php8.2p108.2.28-alt18.2.29-alt1ALT-PU-2025-4317-2377999Fixed
php8.2p10_e2k8.2.28-alt18.2.29-alt1ALT-PU-2025-5261-1-Fixed
php8.2c10f28.2.28-alt18.2.29-alt1ALT-PU-2025-4322-2377997Fixed
php8.2p118.2.28-alt18.2.29-alt1ALT-PU-2025-4202-2377802Fixed
php8.3sisyphus8.3.18-alt18.3.27-alt1ALT-PU-2025-4166-2377717Fixed
php8.3sisyphus_e2k8.3.18-alt18.3.24-alt1ALT-PU-2025-4715-1-Fixed
php8.3sisyphus_riscv648.3.18-alt18.3.27-alt1ALT-PU-2025-4336-1-Fixed
php8.3sisyphus_loongarch648.3.18-alt18.3.27-alt1ALT-PU-2025-4276-1-Fixed
php8.3c10f28.3.18-alt18.3.24-alt1ALT-PU-2025-4370-2377996Fixed
php8.3p118.3.18-alt18.3.24-alt1ALT-PU-2025-4313-2377994Fixed
php8.4sisyphus8.4.5-alt18.4.15-alt1ALT-PU-2025-4368-1377993Fixed
php8.4sisyphus_e2k8.4.5-alt18.4.13-alt1ALT-PU-2025-4713-1-Fixed
php8.4sisyphus_riscv648.4.5-alt18.4.15-alt1ALT-PU-2025-4389-1-Fixed
php8.4sisyphus_loongarch648.4.5-alt18.4.15-alt1ALT-PU-2025-4393-1-Fixed
php8.4p118.4.5-alt18.4.13-alt1ALT-PU-2025-4406-2378211Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.1.0
      End excluding
      8.1.32

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.2.0
      End excluding
      8.2.28

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.3.0
      End excluding
      8.3.19

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.4.0
      End excluding
      8.4.5