cbcvebase.
CVE-2025-2950
published 2025-04-18

CVE-2025-2950: IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i…

PriorityP428medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.27%
18.8th percentile
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmi
ibmi
ibmi
ibmi
lodash.unsetlodash.unset>= 4.0.0 < 4.18.04.18.0
lodashlodash>= 0 < 4.18.04.18.0
lodashlodash-amd>= 0 < 4.18.04.18.0
lodashlodash-es>= 0 < 4.18.04.18.0

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
ghsa6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.