MEDIUM
GHSA-8v5x-6vv5-jv4g
amphp/http Host Header Injection vulnerability
Quick fix
GHSA-8v5x-6vv5-jv4g — amphp/http: upgrade to the fixed version with the command below.
composer require amphp/http:^1.0.1Details
amphp/http versions before 1.0.1 allows an attacker to supply invalid input in the Host header which may lead to various type of Host header injection attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/amphp/http/pull/4[WEB]
- https://github.com/amphp/http/commit/16e465fa82555104d1cff98cb8e412295a380214[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/amphp/http/2018-03-15.yaml[WEB]
- https://github.com/amphp/http[PACKAGE]
- https://github.com/amphp/http/releases/tag/v1.0.1[WEB]