Server-Side Request Forgery (SSRF) in PHP - CVE-2025-1220
Published: July 4, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of the null byte in the fsockopen() function implementation when handling hostnames. A remote attacker can pass a specially crafted hostname to the application and force it to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Debian Linux
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Ubuntu
openEuler
Fedora
EasyApache
libzip-tools
libzip
libzip-devel
php-pear
php-pecl-zip
php-pecl-rrd
php-pecl-xdebug
php-pecl-apcu-devel
apcu-panel
php-pecl-apcu
php7.0 (Ubuntu package)
php-mysqlnd
php
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-snmp
php-soap
php-xml
php-xmlrpc
php-ldap
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-devel
php-embedded
php-enchant
php-fpm
php-mbstring
php-gd
php-gmp
php-intl
php-json
php-ffi
php-debugsource
php-debuginfo
php-sodium
php-tidy
php-help
php8.1 (Ubuntu package)
php8.2 (Debian package)
How to mitigate CVE-2025-1220
EasyApache - update to 4 25-22
libzip-tools - update to 1.6.1-1
libzip - update to 1.6.1-1
libzip-devel - update to 1.6.1-1
php-pear - update to 1.10.13-1.0.1
php-pecl-zip - update to 1.18.2-1
php-pecl-rrd - update to 2.0.1-1
php-pecl-xdebug - update to 2.9.5-1
php-pecl-apcu-devel - update to 5.1.18-1
apcu-panel - update to 5.1.18-1
php-pecl-apcu - update to 5.1.18-1
php7.0 (Ubuntu package) - addressed in versions 7.0.33-0ubuntu0.16.04.16+esm16, 7.0.33-0ubuntu0.16.04.16+esm18, 7.2.24-0ubuntu0.18.04.17+esm9, 7.2.24-0ubuntu0.18.04.17+esm11, 7.4.3-4ubuntu2.29+esm1, 7.4.3-4ubuntu2.29+esm2
php-mysqlnd - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-odbc - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-opcache - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-pdo - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-pgsql - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-process - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-snmp - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-soap - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-xml - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-xmlrpc - update to 7.4.33-3.0.1
php-ldap - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-bcmath - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-cli - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-common - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-dba - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-dbg - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-devel - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-embedded - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-enchant - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-fpm - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-mbstring - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-gd - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-gmp - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-intl - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-json - update to 7.4.33-3.0.1
php-ffi - addressed in versions 7.4.33-3.0.1, 8.3.29-1
php-mbstring - addressed in versions 8.0.30-10, 8.3.23-1
php-ldap - addressed in versions 8.0.30-10, 8.3.23-1
php-intl - addressed in versions 8.0.30-10, 8.3.23-1
php-gmp - addressed in versions 8.0.30-10, 8.3.23-1
php-gd - addressed in versions 8.0.30-10, 8.3.23-1
php-fpm - addressed in versions 8.0.30-10, 8.3.23-1
php-ffi - addressed in versions 8.0.30-10, 8.3.23-1
php-enchant - addressed in versions 8.0.30-10, 8.3.23-1
php-embedded - addressed in versions 8.0.30-10, 8.3.23-1
php-devel - addressed in versions 8.0.30-10, 8.3.23-1
php-debugsource - addressed in versions 8.0.30-10, 8.3.23-1
php-debuginfo - addressed in versions 8.0.30-10, 8.3.23-1
php-odbc - addressed in versions 8.0.30-10, 8.3.23-1
php-opcache - addressed in versions 8.0.30-10, 8.3.23-1
php-pdo - addressed in versions 8.0.30-10, 8.3.23-1
php-pgsql - addressed in versions 8.0.30-10, 8.3.23-1
php-process - addressed in versions 8.0.30-10, 8.3.23-1
php-snmp - addressed in versions 8.0.30-10, 8.3.23-1
php-soap - addressed in versions 8.0.30-10, 8.3.23-1
php-sodium - addressed in versions 8.0.30-10, 8.3.23-1
php-tidy - addressed in versions 8.0.30-10, 8.3.23-1
php-xml - addressed in versions 8.0.30-10, 8.3.23-1
php-help - addressed in versions 8.0.30-10, 8.3.23-1
php-mysqlnd - addressed in versions 8.0.30-10, 8.3.23-1
php - addressed in versions 8.0.30-10, 8.3.23-1
php-bcmath - addressed in versions 8.0.30-10, 8.3.23-1
php-cli - addressed in versions 8.0.30-10, 8.3.23-1
php-common - addressed in versions 8.0.30-10, 8.3.23-1
php-dba - addressed in versions 8.0.30-10, 8.3.23-1
php-dbg - addressed in versions 8.0.30-10, 8.3.23-1
php8.1 (Ubuntu package) - addressed in versions 8.1.2-1ubuntu2.22, 8.3.6-0ubuntu0.24.04.5, 8.4.5-1ubuntu1.1
php8.2 (Debian package) - update to 8.2.29-1~deb12u1
php - addressed in versions 8.3.23-1.fc41, 8.4.10-1.fc42
php-sodium - update to 8.3.29-1
External References
Related Security Bulletins
- Multiple vulnerabilities in PHP
- Fedora 42 update for php
- Fedora 41 update for php
- cPanel EasyApache4 update for PHP
- openEuler 22.03 LTS SP4 update for php
- openEuler 22.03 LTS SP3 update for php
- openEuler 20.03 LTS SP4 update for php
- Ubuntu update for php8.1
- openEuler 24.03 LTS SP2 update for php
- openEuler 24.03 LTS SP1 update for php
- openEuler 24.03 LTS update for php
- Debian update for php8.2
- Ubuntu update for php7.0
- Ubuntu update for php7.0
- Red Hat Enterprise Linux 9 update for the php:8.2 module
- Red Hat Enterprise Linux 8 update for the php:8.2 module
- Anolis OS update for php
- Red Hat Enterprise Linux 8 update for the php:7.4 module
- Anolis OS update for php:7.4 module