CVE-2025-64500
ADVISORY - githubSummary
Description
The Request class improperly interprets some PATH_INFO in a way that leads to representing some URLs with a path that doesn't start with a /. This can allow bypassing some access control rules that are built with this /-prefix assumption.
Resolution
The Request class now ensures that URL paths always start with a /.
The patch for this issue is available here for branch 5.4.
Credits
We would like to thank Andrew Atkinson for discovering the issue, Chris Smith for reporting it and Nicolas Grekas for providing the fix.
EPSS Score: 0.02482 (0.853)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Use of Non-Canonical URL Paths for Authorization Decisions
ADVISORY - github
Use of Non-Canonical URL Paths for Authorization Decisions
NIST
CREATED
UPDATED
ADVISORY IDCVE-2025-64500
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.3highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-3rg7-wf37-54rm
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.3highDebian
CREATED
UPDATED
ADVISORY IDCVE-2025-64500
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2025-64500
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumChainguard
CREATED
UPDATED
ADVISORY ID
CGA-mmqg-729v-84wf
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-