CVE-2025-1220

LOW

PHP 8.1-8.4 fsockopen - Null Byte Hostname Validation Bypass

Title source: manual
STIX 2.1

Description

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.

Scores

CVSS v3 3.7
EPSS 0.0016
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
php/php 8.1.0 - 8.1.33
Published Jul 13, 2025
Tracked Since Feb 18, 2026