{"id":"GHSA-8v5x-6vv5-jv4g","summary":"amphp/http Host Header Injection vulnerability","details":"amphp/http versions before 1.0.1 allows an attacker to supply invalid input in the Host header which may lead to various type of Host header injection attacks.","modified":"2024-11-29T05:32:49.667467Z","published":"2024-05-15T17:52:41Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-15T17:52:41Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/amphp/http/pull/4"},{"type":"WEB","url":"https://github.com/amphp/http/commit/16e465fa82555104d1cff98cb8e412295a380214"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/amphp/http/2018-03-15.yaml"},{"type":"PACKAGE","url":"https://github.com/amphp/http"},{"type":"WEB","url":"https://github.com/amphp/http/releases/tag/v1.0.1"}],"affected":[{"package":{"name":"amphp/http","ecosystem":"Packagist","purl":"pkg:composer/amphp/http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"versions":["v1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-8v5x-6vv5-jv4g/GHSA-8v5x-6vv5-jv4g.json"}}],"schema_version":"1.9.0"}