[meta] Track changes to hacked host header protections in Symfony and PHP

Created on 27 January 2015, about 10 years ago
Updated 22 March 2025, 14 days ago

Problem/Motivation

A number of issues have been opened to mitigate potential host header vulnerabilities:

Some of the protections are in addition to ones in Symfony. There is currently active discussion on the Symfony side about increasing protections in Request::getHost(), or in PHP itself.

If some of these changes get in, some code in Drupal, such as the host header length test, may removed as redundant.

Proposed resolution

Keep aware of changes in Symfony and PHP. Open child issues as necessary.

📌 Task
Status

Active

Version

11.0 🔥

Component

base system

Created by

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024