CVE-2025-1734
MediumAdvisory
Published 14 Mar 2025In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 11
- of 17,781 indexed, latest versions
- Container images
- 10
- deployed by those charts
- Fix available
- 6 of 6
- affected packages
Streams HTTP wrapper does not fail for headers with invalid name and no colon
Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| libphpbitnami | 7.4.33-1 | 8.1.32 | 1 |
| phpbitnami | 7.4.33-2 | 8.1.32 | 1 |
| php7.4deb | 7.4.3-4ubuntu2.6, 7.4.3-4ubuntu2.12, 7.4.3-4ubuntu2.13, 7.4.3-4ubuntu2.15+1 more | 7.4.3-4ubuntu2.29 | 5 |
| php8.1deb | 8.1.2-1ubuntu2.3, 8.1.2-1ubuntu2.14 | 8.1.2-1ubuntu2.21 | 2 |
| php8.2deb | 8.2.7-1~deb12u1 | 8.2.28-1~deb12u1 | 1 |
| php8.3deb | 8.3.6-0ubuntu0.24.04.3 | 8.3.6-0ubuntu0.24.04.4 | 1 |
- OSV records
- BIT-libphp-2025-1734BIT-php-2025-1734DEBIAN-CVE-2025-1734UBUNTU-CVE-2025-1734
- Also known as
- BIT-php-min-2025-1734, GHSA-pcmh-g36c-qc44, USN-7400-1
Charts affected
11 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zabbixcetic | 3.1.3 | 1 of 5See more | 33,725 |
| snipeitt3n | 3.4.1 | 1 of 2See more | 18,509 |
| zabbix-serveraekondratievVerified publisher | 1.0.6 | 1 of 4See more | 30,668 |
| zabbix-server-mysqlfermosit | 3.0.2 | 1 of 4See more | 12,840 |
| equizequiz | 0.0.1 | 1 of 3See more | 7,541 |
| equizequiz-chart | 0.0.1 | 1 of 3See more | 7,541 |
| nominatimheywood8-helm-chartsVerified publisher | 3.10.8 | 1 of 3See more | 14,290 |
| kc-chartkc-chart | 1.0.0 | 1 of 3See more | 8,860 |
| phppgadminkfirfer | 0.1.12 | 1 of 1See more | 10,248 |
| nominatimnominatim-chart | 1.3.0 | 1 of 3See more | 22,658 |
| owncloudth-chartsVerified publisher | 0.2.1 | 1 of 1See more | 10,006 |
Container images carrying it
10 by charts deploying them
A fixed version is listed for 6 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| yzhou442/ | a3f7ca69e28d | libphp php | 8.1.32 8.1.32 | 2 |
| jhoncytech/ | 18c3ca1f411e | php8.2 | 8.2.28-1~deb12u1 | 1 |
| kfirfer/ | 2efb4a5d74a3 | php7.4 | 7.4.3-4ubuntu2.29 | 1 |
| mediagis/ | c15e941485ef | php7.4 | 7.4.3-4ubuntu2.29 | 1 |
| mediagis/ | d0eae7b51374 | php8.1 | 8.1.2-1ubuntu2.21 | 1 |
| owncloud/ | 51d9b74fc2a8 | php7.4 | 7.4.3-4ubuntu2.29 | 1 |
| snipe/ | 55fb7636a98c | php7.4 | 7.4.3-4ubuntu2.29 | 1 |
| zabbix/ | 0e5f69c4c54e | php8.3 | 8.3.6-0ubuntu0.24.04.4 | 1 |
| zabbix/ | 01de79c31391 | php7.4 | 7.4.3-4ubuntu2.29 | 1 |
| zabbix/ | 99e9a090b516 | php8.1 | 8.1.2-1ubuntu2.21 | 1 |