CVE-2025-52479
Last modified
CVE-2025-52479 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF characters. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF characters. If user input was not otherwise escaped or protected, this can lead to a CRLF injection attack. Users of HTTP.jl should upgrade immediately to HTTP.jl v1.10.17, and users of URIs.jl should upgrade immediately to URIs.jl v1.6.0. The check for valid URIs is now in the URI.jl package, and the latest version of HTTP.jl incorporates that fix. As a workaround, manually validate any URIs before passing them on to functions in this package.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-52479?
How severe is CVE-2025-52479?
How do I fix CVE-2025-52479?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52473liboqs is a C-language cryptographic library that provides i…5.5
- CVE-2025-52474WeGIA is a web manager for charitable institutions. Prior to…9.8
- CVE-2025-52475Chamilo is a learning management system. Prior to version 1.…6.1
- CVE-2025-52476Chamilo is a learning management system. Prior to version 1.…6.1
- CVE-2025-52477Octo-STS is a GitHub App that acts like a Security Token Ser…8.6
- CVE-2025-52478n8n is a workflow automation platform. From 1.77.0 to before…5.4
- CVE-2025-5248A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-52480Registrator is a GitHub app that automates creation of regis…9.8
- CVE-2025-52482Chamilo is a learning management system. Prior to version 1.…8.3
- CVE-2025-52483Registrator is a GitHub app that automates creation of regis…9.8
- CVE-2025-52484RISC Zero is a general computing platform based on zk-STARKs…2.7
- CVE-2025-52485DNN (formerly DotNetNuke) is an open-source web content mana…5.4
Are you affected by CVE-2025-52479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
