CVE-2016-5385

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Published: 2016-07-19 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2016-5385 is rated High Risk (69.7/100): CVSS High severity, with high exploitation likelihood (EPSS 83.49%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +2.59% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2016-5385

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-12 80.90% 83.49% +2.59%
2 2026-06-07 83.50% 80.90% -2.60%
3 2026-05-24 83.50%

Full EPSS history (49 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2016-5385

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.1 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 5.9 [email protected]
5.1 2.0 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
4.9 6.4 [email protected]

Weakness enumeration for CVE-2016-5385

GitHub Security Advisory for CVE-2016-5385

GHSA-m6ch-gg5f-wxx3 · Severity: high · Ecosystem: composer — HTTP Proxy header vulnerability

OS Trackers for CVE-2016-5385

vendor priority summary link
gentoo normal CVE-2016-5385: 1 GLSA(s) (201611-22), 1 atom(s) (dev-lang/php); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-5385
redhat medium https://access.redhat.com/security/cve/CVE-2016-5385
suse medium CVE-2016-5385 severity moderate: SUSE including 348 source package names (apache2-mod_php5-5.5.14-68.1, apache2-mod_php53, …), 560 product×package rows across 20 product lines (SUSE Enterprise Storage 7.1, SUSE Liberty Linux 7, … (20 product lines)): Known Not Affected 419, Fixed 141. https://www.suse.com/security/cve/CVE-2016-5385/
ubuntu medium CVE-2016-5385 medium priority: Ubuntu including 2 source packages (php5, php7.0), 10 status rows across 5 suites (precise, trusty, upstream, wily, xenial): DNE 4, released 4, ignored 1, needs-triage 1. https://ubuntu.com/security/CVE-2016-5385

Affected software / configurations for CVE-2016-5385

Vendor Product Version Raw CPE
oracle communications_user_data_repository 10.0.0 cpe:2.3:a:oracle:communications_user_data_repository:10.0.0:*:*:*:*:*:*:*
oracle communications_user_data_repository 10.0.1 cpe:2.3:a:oracle:communications_user_data_repository:10.0.1:*:*:*:*:*:*:*
oracle communications_user_data_repository 12.0.0 cpe:2.3:a:oracle:communications_user_data_repository:12.0.0:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 12.2.2 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 12.3.2 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.2:*:*:*:*:*:*:*
oracle linux 6 cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*
oracle linux 7 cpe:2.3:o:oracle:linux:7:-:*:*:*:*:*:*
fedoraproject fedora 23 cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
fedoraproject fedora 24 cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
hp storeever_msl6480_tape_library_firmware <= 5.09 cpe:2.3:o:hp:storeever_msl6480_tape_library_firmware:*:*:*:*:*:*:*:*
hp system_management_homepage <= 7.5.5.0 cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:*
php php >= 5.5.0, < 5.5.38 cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
php php >= 5.6.0, < 5.6.24 cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
php php >= 7.0.0, <= 7.0.8 cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
redhat enterprise_linux_desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
debian debian_linux 8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
opensuse leap 42.1 cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
drupal drupal >= 8.0.0, < 8.1.7 cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

References for CVE-2016-5385

URL Tags
http://lists.opensuse.org/opensuse-updates/2016-08/msg00003.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1609.html Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1610.html Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1611.html Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1612.html Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1613.html Broken Link Third Party Advisory
http://www.debian.org/security/2016/dsa-3631 Third Party Advisory
http://www.kb.cert.org/vuls/id/797896 Third Party Advisory US Government Resource
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
http://www.securityfocus.com/bid/91821 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1036335 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1353794 Issue Tracking Third Party Advisory VDB Entry
https://github.com/guzzle/guzzle/releases/tag/6.2.1 Release Notes Third Party Advisory
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05333297 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
https://httpoxy.org/ Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RMYXAVNYL2MOBJTFATE73TOVOEZYC5R/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXFEIMZPSVGZQQAYIQ7U7DFVX3IBSDLF/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZOIUYZDBWNDDHC6XTOLZYRMRXZWTJCP/
https://security.gentoo.org/glsa/201611-22 Third Party Advisory
https://www.drupal.org/SA-CORE-2016-003 Third Party Advisory
cvelogic Threat Intelligence