CVE-2025-1220 | PHP up to 8.1.32/8.2.28/8.3.22/8.4.9 Null Character fsockopen Hostname server-side request forgery (GHSA-3cr5-j632-f35r / EUVD-2025-21274)
A vulnerability classified as critical was found in PHP up to 8.1.32/8.2.28/8.3.22/8.4.9. Affected by this vulnerability is the function fsockopen of the component Null Character Handler. Such manipulation of the argument Hostname leads to server-side request forgery.
This vulnerability is documented as CVE-2025-1220. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.