{"id":"GHSA-9jxr-mwpp-w643","summary":"Improper header validation in httpsoft/http-message","details":"### Impact\n\nImproper header parsing. An attacker could sneak in a newline (`\\n`) into both the header names and values. While the specification states that `\\r\\n\\r\\n` is used to terminate the header list, many servers in the wild will also accept `\\n\\n`.\n\n### Patches\n\nThe issue is patched in 1.0.12.\n\n### Workarounds\n\nThere are no known workarounds.\n\n### References\n\n* https://www.rfc-editor.org/rfc/rfc7230#section-3.2.4","modified":"2024-12-06T05:39:44.940674Z","published":"2023-04-21T20:27:12Z","database_specific":{"cwe_ids":["CWE-436"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-04-21T20:27:12Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/guzzle/psr7/security/advisories/GHSA-wxmh-65f7-jcvw"},{"type":"WEB","url":"https://github.com/httpsoft/http-message/security/advisories/GHSA-9jxr-mwpp-w643"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29197"},{"type":"PACKAGE","url":"https://github.com/httpsoft/http-message"}],"affected":[{"package":{"name":"httpsoft/http-message","ecosystem":"Packagist","purl":"pkg:composer/httpsoft/http-message"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.12"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-9jxr-mwpp-w643/GHSA-9jxr-mwpp-w643.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}