CVE-2025-59151

Source
https://cve.org/CVERecord?id=CVE-2025-59151
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59151.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59151
Aliases
  • GHSA-5v79-p56f-x7c4
Published
2025-10-27T19:42:59.596Z
Modified
2026-07-15T01:48:53.987491792Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L CVSS Calculator
Summary
Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
Details

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with the .lp extension, the application performs a redirect without properly sanitizing the input. An attacker can inject carriage return and line feed characters (%0d%0a) to manipulate both the headers and the content of the HTTP response. This enables the injection of arbitrary HTTP response headers, potentially leading to session fixation, cache poisoning, and the weakening or bypassing of browser-based security mechanisms such as Content Security Policy or X-XSS-Protection. This vulnerability is fixed in 6.3.

Database specific
{
    "cwe_ids": [
        "CWE-113",
        "CWE-93"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59151.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/pi-hole/web

Affected ranges

Type
GIT
Repo
https://github.com/pi-hole/web
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

0.*
0.1
1.*
1.0
1.1
1.2
1.2.1
2.*
2.0.0
2.1.0
2.1.1
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.2
v1.3
v1.4
v1.4.1
v1.4.2
v1.4.3
v1.4.3.1
v1.4.3.1a
v1.4.4
v1.4.4.1
v1.4.4.2
v2.*
v2.0
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.5
v2.1
v2.1.0-alpha-1
v2.1.0-beta
v2.1.2
v2.2
v2.2.0
v2.3
v2.3.1
v2.4
v2.5
v2.5.1
v2.5.2
v3.*
v3.0
v3.0.1
v3.0.1a
v3.1
v3.2
v3.2.1
v3.3
v4.*
v4.0
v4.1
v4.1.1
v4.2
v4.3
v4.3.2
v4.3.3
v5.*
v5.0
v5.1
v5.1.1
v5.10
v5.10.1
v5.11
v5.12
v5.13
v5.14
v5.14.1
v5.14.2
v5.15
v5.15.1
v5.16
v5.17
v5.18
v5.18.1
v5.18.2
v5.18.3
v5.18.4
v5.19
v5.2
v5.2.1
v5.2.2
v5.20
v5.20.1
v5.20.2
v5.21
v5.3
v5.3.1
v5.3.2
v5.4
v5.5
v5.5.1
v5.6
v5.7
v5.8
v5.9
v6.*
v6.0
v6.0.1
v6.0.2
v6.1
v6.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59151.json"