CVE-2025-30221 Details
Description
Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available.
A vulnerability allowing HTTP response header injection has been identified in Shopify Pitchfork versions prior to 0.11.0, when used with Rack 3. This issue can lead to HTTP request/response splitting.
Users are advised to upgrade to Pitchfork version 0.11.0 or later. Instructions for upgrading can be found in the Pitchfork repository on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 27, 2025CISA-ADP
Assessed Mar 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Shopify/pitchfork/commit/17ed9b61bf9f58957065f7405b66102daf86bf55 | [email protected] | Source CodeVendor |
| https://github.com/Shopify/pitchfork/security/advisories/GHSA-pfqj-w6r6-g86v | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shopify Pitchfork | All versions |
CPE
Remediation
| |
| Rack | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2025 | New CVE Received | [email protected] |
Volerion