HTTP Response Header Injection in Pitchfork Server by Shopify
CVE-2025-30221
What is CVE-2025-30221?
Pitchfork, a preforking HTTP server designed for Rack applications, is susceptible to an HTTP Response Header Injection vulnerability when utilized in conjunction with Rack 3. This security flaw enables attackers to inject arbitrary headers into HTTP responses, potentially leading to security issues such as content spoofing or session fixation. The issue is present in all versions prior to 0.11.0, and it has been effectively resolved in the version 0.11.0 release. Users are advised to upgrade to ensure their applications remain secure. Unfortunately, there are no known workarounds available for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pitchfork < 0.11.0
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
