216.73.217.22

CVE-2025-61689

· Published 10/10/2025 17:15 · Modified 10/10/2025 17:15

Labels: CVE-2025-61689 2025-10-10CVE-2025-61689CWE-113[email protected]

Essential information

Published
10/10/2025 17:15
Modified
10/10/2025 17:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl did not validate header names/values for illegal characters, allowing CRLF-based header injection and response splitting. This enables HTTP response splitting and header injection, leading to cache poisoning, XSS, session fixation, and more. This issue is fixed in HTTP.jl `v1.10.19`.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
julia / http.jl cpe:2.3:a:julia:http.jl:<1.10.19:*:*:*:*:*:*:*
julia / http.jl cpe:2.3:a:julia:http.jl:1.10.19:*:*:*:*:*:*:*

References