Vulnerability record · CVE-2016-5385 · published 19 July 2016
CVE-2016-5385: PHP httpoxy HTTP_PROXY header namespace conflict enables proxy redirection
Oracle · Communications User Data Repository
PHP through 7.0.8 fails to address RFC 3875 section 4.1.18 namespace conflicts, so a client-supplied Proxy header is exposed to applications as the HTTP_PROXY environment variable. Applications that read getenv('HTTP_PROXY') or run under CGI can have their outbound HTTP traffic silently redirected to an attacker-controlled proxy. This is the httpoxy class of issue and affects a wide range of packaged PHP deployments.
Description
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.1) and very high EPSS with broad multi-vendor exposure, though exploitation requires an application that actually consumes HTTP_PROXY.
What it is
PHP through 7.0.8 fails to address RFC 3875 section 4.1.18 namespace conflicts, so a client-supplied Proxy header is exposed to applications as the HTTP_PROXY environment variable. Applications that read getenv('HTTP_PROXY') or run under CGI can have their outbound HTTP traffic silently redirected to an attacker-controlled proxy. This is the httpoxy class of issue and affects a wide range of packaged PHP deployments.
Impact
An attacker can redirect an application's outbound HTTP requests through a proxy they control, exposing credentials, session tokens and request bodies, and enabling manipulation of responses returned to the application.
Attack surface
Reachable remotely over the network by sending a crafted Proxy header in an HTTP request; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). Only applications that read HTTP_PROXY or run in a CGI configuration are actually exposed.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.50 (98.9th percentile), and the httpoxy.org advisory plus multiple vendor errata indicate broad public knowledge of the technique.
What to do
- Upgrade PHP to a release that strips or blocks the Proxy header from the CGI environment, and apply vendor errata for Red Hat, Debian, SUSE, Fedora, Oracle, HPE and Drupal components.
- Where patching is delayed, configure the web server or CGI layer to unset the HTTP_PROXY environment variable before invoking PHP.
- Change application code to avoid reading getenv('HTTP_PROXY') for outbound proxy configuration, and use explicit configuration instead.
- Audit outbound HTTP client libraries (for example Guzzle) and update to versions that ignore the untrusted Proxy header.
- Restrict egress traffic from application servers so outbound requests cannot reach arbitrary proxy endpoints.
Detection
- Inspect HTTP request logs for requests carrying a Proxy header, especially unusual or external source addresses.
- Monitor outbound HTTP connections from application servers for traffic to unexpected proxy hosts or ports.
- Review application and proxy logs for credential or token exposure correlated with requests containing a Proxy header.
- Check PHP and web server configurations for HTTP_PROXY handling and confirm the variable is cleared in CGI environments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-5385 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-5385), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.