HTTP Response Header Injection in Pitchfork Server by Shopify
CVE-2025-30221

4.3MEDIUM

Key Information:

Vendor

Shopify

Status
Vendor
CVE Published:
27 March 2025

What is CVE-2025-30221?

Pitchfork, a preforking HTTP server designed for Rack applications, is susceptible to an HTTP Response Header Injection vulnerability when utilized in conjunction with Rack 3. This security flaw enables attackers to inject arbitrary headers into HTTP responses, potentially leading to security issues such as content spoofing or session fixation. The issue is present in all versions prior to 0.11.0, and it has been effectively resolved in the version 0.11.0 release. Users are advised to upgrade to ensure their applications remain secure. Unfortunately, there are no known workarounds available for this vulnerability.

Affected Version(s)

pitchfork < 0.11.0

References

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30221 : HTTP Response Header Injection in Pitchfork Server by Shopify