{"id":"GHSA-8v5x-6vv5-jv4g","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8v5x-6vv5-jv4g","summary":"amphp/http Host Header Injection vulnerability","details":"amphp/http versions before 1.0.1 allows an attacker to supply invalid input in the Host header which may lead to various type of Host header injection attacks.","published":"2024-05-15T17:52:41Z","modified":"2024-11-29T05:51:32.132276Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"amphp/http","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/amphp/http/pull/4","label":"amphp/http#4"},"references":[{"type":"WEB","url":"https://github.com/amphp/http/pull/4"},{"type":"WEB","url":"https://github.com/amphp/http/commit/16e465fa82555104d1cff98cb8e412295a380214"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/amphp/http/2018-03-15.yaml"},{"type":"PACKAGE","url":"https://github.com/amphp/http"},{"type":"WEB","url":"https://github.com/amphp/http/releases/tag/v1.0.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:51:32.132276Z"}}