{"id":"GHSA-x5mq-jjr3-vmx6","summary":"Missing validation of header name and value in codeigniter4/framework","details":"### Impact\nLack of proper header validation for its name and value. The potential attacker can construct deliberately malformed headers with `Header` class. This could disrupt application functionality, potentially causing errors or generating invalid HTTP requests. In some cases, these malformed requests might lead to a DoS scenario if a remote service’s web application firewall interprets them as malicious and blocks further communication with the application.\n\n### Patches\nUpgrade to v4.5.8 or later.\n\n### Workarounds\nValidate HTTP header keys and/or values if using user-supplied values before passing them to `Header` class.\n\n### Differences from CVE-2023-29197\n\n1. **Affected Software**:\n    * CVE-2023-29197 specifically addresses a vulnerability in the `guzzlehttp/psr7` library.\n    * The reported issue in this Security Advisory is within the **CodeIgniter4** framework and does not depend on or use the `guzzlehttp/psr7` library.\n\n2. **Root Cause and Implementation**:\n    * The vulnerability reported arises from an issue in the **Header class** of CodeIgniter4, which is unrelated to the functionality or implementation of `guzzlehttp/psr7`.\n\n3. **Scope of Impact**:\n    * The vulnerability described in this Security Advisory affects applications built with the **CodeIgniter4** framework, which does not use or rely on the `guzzlehttp/psr7` library.\n\n### References\n* https://datatracker.ietf.org/doc/html/rfc7230#section-3.2\n* https://github.com/advisories/GHSA-wxmh-65f7-jcvw","aliases":["CVE-2025-24013"],"modified":"2026-02-04T04:21:17.711108Z","published":"2025-01-21T21:13:40Z","related":["CVE-2025-24013"],"database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-01-21T21:13:40Z","nvd_published_at":"2025-01-20T16:15:28Z","cwe_ids":["CWE-436"]},"references":[{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-x5mq-jjr3-vmx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24013"},{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/commit/5f8aa24280fb09947897d6b322bf1f0e038b13b6"},{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc7230#section-3.2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wxmh-65f7-jcvw"},{"type":"PACKAGE","url":"https://github.com/codeigniter4/CodeIgniter4"}],"affected":[{"package":{"name":"codeigniter4/framework","ecosystem":"Packagist","purl":"pkg:composer/codeigniter4/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.8"}]}],"versions":["4.0.0","4.0.0-rc.4","v4.0.0-alpha.3","v4.0.0-alpha.4","v4.0.0-alpha.5","v4.0.0-beta.1","v4.0.0-beta.2","v4.0.0-beta.3","v4.0.0-beta.4","v4.0.0-rc.1","v4.0.0-rc.2","v4.0.0-rc.2.1","v4.0.0-rc.3","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.1.0","v4.1.1","v4.1.2","v4.1.3","v4.1.4","v4.1.5","v4.1.6","v4.1.7","v4.1.8","v4.1.9","v4.2.0","v4.2.1","v4.2.10","v4.2.11","v4.2.12","v4.2.2","v4.2.3","v4.2.4","v4.2.5","v4.2.6","v4.2.7","v4.2.8","v4.2.9","v4.3.0","v4.3.1","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.4.0","v4.4.1","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.4.6","v4.4.7","v4.4.8","v4.5.0","v4.5.1","v4.5.2","v4.5.3","v4.5.4","v4.5.5","v4.5.6","v4.5.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-x5mq-jjr3-vmx6/GHSA-x5mq-jjr3-vmx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}