Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      June 5, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 5, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 5, 2025

      CodeSOD: Integral to a Database Read

      June 5, 2025

      Players aren’t buying Call of Duty’s “error” excuse for the ads Activision started forcing into the game’s menus recently

      June 4, 2025

      In Sam Altman’s world, the perfect AI would be “a very tiny model with superhuman reasoning capabilities” for any context

      June 4, 2025

      Sam Altman’s ouster from OpenAI was so dramatic that it’s apparently becoming a movie — Will we finally get the full story?

      June 4, 2025

      One of Microsoft’s biggest hardware partners joins its “bold strategy, Cotton” moment over upgrading to Windows 11, suggesting everyone just buys a Copilot+ PC

      June 4, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Enable Flexible Pattern Matching with Laravel’s Case-Insensitive Str::is Method

      June 5, 2025
      Recent

      Enable Flexible Pattern Matching with Laravel’s Case-Insensitive Str::is Method

      June 5, 2025

      Laravel OpenRouter

      June 5, 2025

      This Week in Laravel: Starter Kits, Alpine, PDFs and Roles/Permissions

      June 5, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      FOSS Weekly #25.23: Helwan Linux, Quarkdown, Konsole Tweaks, Keyboard Shortcuts and More Linux Stuff

      June 5, 2025
      Recent

      FOSS Weekly #25.23: Helwan Linux, Quarkdown, Konsole Tweaks, Keyboard Shortcuts and More Linux Stuff

      June 5, 2025

      Grow is a declarative website generator

      June 5, 2025

      Raspberry Pi 5 Desktop Mini PC: Benchmarking

      June 5, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-48865 – Fabio HTTP Hop-by-Hop Header Manipulation Vulnerability

    CVE-2025-48865 – Fabio HTTP Hop-by-Hop Header Manipulation Vulnerability

    May 30, 2025

    CVE ID : CVE-2025-48865

    Published : May 30, 2025, 7:15 a.m. | 2 hours, 21 minutes ago

    Description : Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like X-Forwarded-Host and X-Forwarded-Port when routing requests to backend applications. Since the receiving application should trust these headers, allowing HTTP clients to remove or modify them creates potential security vulnerabilities. Some of these custom headers can be removed and, in certain cases, manipulated. The attack relies on the behavior that headers can be defined as hop-by-hop via the HTTP Connection header. This issue has been patched in version 1.6.6.

    Severity: 9.1 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-48487 – FreeScout Flash Message Cross-Site Scripting (XSS) Vulnerability
    Next Article CVE-2025-48486 – FreeScout Cross-Site Scripting (XSS) Vulnerability

    Related Posts

    Security

    UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign

    June 5, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-0691 – Devolutions Server Access Control Bypass

    June 5, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Distribution Release: Ubuntu Kylin 25.04

    News & Updates

    CVE-2025-48942 – vLLM JSON Schema Deserialization Denial of Service

    Common Vulnerabilities and Exposures (CVEs)

    Rilasciata Arch Linux Enhance Xenial (ALEX) aggiornata a maggio 2025

    Linux

    The race to AI integration

    Artificial Intelligence

    Highlights

    Community managers in action: Leading a developer community for good

    February 25, 2025

    Jumpstarting your career as a community manager Managing communities has always been something I wanted…

    I tried adding Razer’s latest smart home lights to my setup, but I’m not as sold on these standing light bars

    March 16, 2025

    Google’s new Gemini 2.5 models can “reason through their thoughts before responding”

    March 31, 2025

     Getting started with Vuex

    January 9, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.