HTTP Response Header Injection in Pitchfork Server by Shopify
CVE-2025-30221
4.3MEDIUM
What is CVE-2025-30221?
Pitchfork, a preforking HTTP server designed for Rack applications, is susceptible to an HTTP Response Header Injection vulnerability when utilized in conjunction with Rack 3. This security flaw enables attackers to inject arbitrary headers into HTTP responses, potentially leading to security issues such as content spoofing or session fixation. The issue is present in all versions prior to 0.11.0, and it has been effectively resolved in the version 0.11.0 release. Users are advised to upgrade to ensure their applications remain secure. Unfortunately, there are no known workarounds available for this vulnerability.
Affected Version(s)
pitchfork < 0.11.0