On Thu, 9 Jul 2026 at 09:21, Sjoerd Langkemper <[email protected]>
wrote:

> I propose to not allow newlines in header values. Any thoughts on
> this? Should this first raise a deprecation warning before throwing a value
> error?
>


Thanks for noticing this, while header injection vulnerabilities aren't
that common, it's still a problem.

I just wanted to note that the header() function rejects newlines (since
5.1.2):

header("Hello: world\r\nFoo: bar");


Warning: Header may not contain more than a single header, new line
detected in [...]

The header is simply not sent.

https://github.com/php/php-src/blob/9dc29aafa5eecc71a9f9e2c7607b588597a91810/main/SAPI.c#L760

https://github.com/php/php-src/commit/f2415625d4848b503f1fbcc7986211d6eb4aa7df

Craig

Reply via email to