CVE-2025-30221 MEDIUM

CVE-2025-30221: Pitchfork HTTP Request/Response Splitting vulnerability

Vendor Shopify
Product pitchfork
Weakness CWE-113 · HTTP response splitting
Published March 27, 2025
Last update March 27, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available.

Key dates

02Disclosure timeline

March 27, 2025 CVE published
March 27, 2025 Record updated