CVE 8.7 HIGH

HTTP.jl vulnerable to Header injection/Response splitting via header construction._CVE-2025-61689

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:P

Description

HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl did not validate header names/values for illegal characters, allowing CRLF-based header injection and response splitting. This enables HTTP response splitting and header injection, leading to cache poisoning, XSS, session fixation, and more. This issue is fixed in HTTP.jl `v1.10.19`.

Basic Information

ID CVE-2025-61689
Source GitHub_M
Published Oct 10, 2025 at 16:48

Affected Product

Vendor JuliaWeb
Product HTTP.jl
Version < 1.10.19
Affected Versions JuliaWeb HTTP.jl < 1.10.19

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.