CVE-2025-30221 – Pitchfork HTTP Response Header Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2025-30221 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 27, 2025

    Action Type Old Value New Value
    Added Description Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available.
    Added CVSS V3 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
    Added CWE CWE-113
    Added Reference https://github.com/Shopify/pitchfork/commit/17ed9b61bf9f58957065f7405b66102daf86bf55
    Added Reference https://github.com/Shopify/pitchfork/security/advisories/GHSA-pfqj-w6r6-g86v
Share the Post:

Related Posts