In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
We have discovered 415,224 live websites that are affected by CVE-2025-1736.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 415,224 live websites (5.69% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 84 versions ( 16% of all versions) |
| 95,771 websites | |
| 108,386 websites | |
| 21,319 websites | |
| 20,425 websites | |
| 19,403 websites | |
| 15,464 websites | |
| 12,695 websites | |
| 12,086 websites | |
| 9,028 websites | |
| 8,086 websites |
| .com | 168,395 websites |
| .fr | 45,134 websites |
| .org | 19,101 websites |
| .ru | 18,673 websites |
| .net | 12,607 websites |
| .com.br | 11,247 websites |
| .nl | 10,723 websites |
| .de | 7,480 websites |
| .be | 6,828 websites |
| .it | 6,459 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | *,*** | ||
| ********.********.it | *,*** | ||
| ****.*****.com | *,*** | ||
| ****.*******.org | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| *****.com | *,*** | ||
| *******.com | *,*** | ||
| ***********************.com | *,*** |
FAQ