CVE-2025-30221
Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available.
- Fix
- Available
- CVSS 3.0
- 4.3 MEDIUM
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-113
- NVD status
- Deferred
- Published
- 2025-03-27
CVE-2025-30221 at NVD
No indexed exploits for CVE-2025-30221 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-30221 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.