VDB
Sign up
MEDIUM4.0

GHSA-8jp9-mpv9-98rj

amphp/http-client Header leakage on cross-domain redirects

Quick fix

GHSA-8jp9-mpv9-98rj — amphp/http-client: upgrade to the fixed version with the command below.

composer require amphp/http-client:^4.4.0

Details

amphp/http-client has a security weakness that might leak sensitive request headers from the initial request to the redirected host on cross-domain redirects, which were not removed correctly. `Message::setHeaders` does not replace the entire set of headers, but only operates on the headers matching the given array keys.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/amphp/http-client
Introduced in: 4.0.0Fixed in: 4.4.0
Fixcomposer require amphp/http-client:^4.4.0

References