CVE-2025-30221: Shopify Pitchfork
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response Header Injection when used in conjunction with Rack 3. The issue was fixed in Pitchfork release 0.11.0. No known workarounds are available.
Affected products
- Shopify Pitchfork: before 0.11.0 (fixed in 0.11.0)
Published 2025-03-27. Last modified 2026-06-17.