Missing validation of header name and value in codeigniter4/framework
In plain language
Written by AI from the record
CVE-2025-24013 is a CodeIgniter issue where attackers can send specially crafted HTTP headers and get your app to accept injected headers; most small businesses should patch if you’re running CodeIgniter with a public-facing web app.
In CodeIgniter (codeigniter4/framework / CodeIgniter4), improper validation of custom HTTP header names and values allows remote header injection into server requests, without authentication or user interaction.
If you're affected
Injected/malicious headers
Potential request/logic manipulation
Possible data exposure risk
Security control bypass risk
What is it
Imagine your web app is a receptionist that reads information from envelopes (HTTP headers). This bug is like the receptionist letting someone write extra or misleading text on the envelope in a way that the app may treat as legitimate. That can lead to the app making the wrong decisions based on attacker-supplied header content.
Who is affected
This matters if you run a public web application using CodeIgniter (CodeIgniter4 / codeigniter4/framework). Because it doesn’t require authentication or user interaction, anyone who can reach your site over the network may be able to send crafted headers. Only treat it as a risk if an attacker can reach the application endpoints you expose on the internet.
How urgent is it
This is a medium-risk bug pattern (header injection) but there’s no confirmed “known exploited” listing in CISA KEV and no public exploit code found in the provided findings. That means it’s not at the “mass exploitation” level right now. Still, you should upgrade to the fixed version because the trigger is straightforward for remote attackers sending crafted HTTP headers.
What to do — in detail
Confirm exposure
Identify the CodeIgniter version in your app (codeigniter4/framework / CodeIgniter4). If you deploy via Composer, check the locked dependency.
Determine whether your application accepts requests from the public internet (typical web apps do). This vulnerability is triggered by sending crafted HTTP headers to the app.
Compare to fixed versions
codeigniter4/framework is fixed in 4.5.8.
codeigniter / CodeIgniter4 is fixed in 4.5.8.
If you are on any earlier version than 4.5.8, you should upgrade.
Upgrade plan
Upgrade to 4.5.8 (or later) and redeploy.
Check your application’s use of HTTP headers (for example, any code that reads specific custom headers for authentication, routing, feature flags, or tenant selection). Those are the places where injected headers could matter most.
Temporary workaround (only if upgrade is delayed)
If your stack allows it, add/strengthen a reverse proxy or web application firewall (WAF) rule set that rejects unexpected or malformed header names/values.
Ensure the app only trusts the exact headers you intend to use, and avoid using untrusted header values for security decisions.
Note: these are mitigations; the code fix is the proper resolution.
What to monitor after patching
Monitor application logs for unusual header patterns or spikes in requests containing unexpected header names.
Validate that normal client behavior still works and that any header-based features behave as expected.
Technical context
Severity is listed as MEDIUM (CVSS 5.3). The issue is a weakness in HTTP request processing: CodeIgniter does not properly validate custom header names and values, enabling attacker-controlled header injection into server-side request handling. Preconditions from the findings: a remote attacker can send crafted HTTP headers to a CodeIgniter application; authentication and user interaction are not required. In the provided findings, there is no CISA KEV entry and no public exploit code recorded; the EPSS data provided is a prediction only (not treated as confirmed exploitation). Fix: code changes validate header name/value, with the fixed release identified as 4.5.8 for both codeigniter4/framework and CodeIgniter4/codeigniter.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.