# Security Advisory: HTTP.jl, URIs.jl, Registrator.jl, GitForge.jl, and GitHub.jl

**URL:** <https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189>\
**Category:** General Usage\
**Tags:** security\
**Created:** [June 24, 2025, 11:16pm UTC](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189 "2025-06-24T23:16:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![avik](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/avik/32/17_2.png) [@avik](https://discourse.julialang.org/u/avik)\
**Post date:** [June 24, 2025, 11:16pm UTC](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189/1 "2025-06-24T23:16:21Z")

</div>

Security vulnerabilities have been reported in a few Julia packages. We recommend all users upgrade to the latest version of these packages as soon as possible. Each vulnerability has been assigned a CVE and published as a GitHub Security Advisory.

1. The URIs.jl and HTTP.jl packages allowed the construction of URIs containing CR/LF characters. If user input was not otherwise escaped or protected, this can lead to a CRLF injection attack.

2. Lack of validation for user-provided fields in GitForge.jl

3. Command and argument injection in [Registrator.jl](http://registrator.jl).

Each of these three issues were found by _splitline_ from the DEVCORE Research Team. We thank them for their well-researched report and responsible disclosure.

1. Lack of validation for user-provided fields in GitHub.jl

We recommend everyone move to the latest versions of each of these packages as soon as possible. In particular, if you are using Registrator.jl in your organisations, you should upgrade immediately. The combination of the first three issues can cause remote code execution inside a Registrator instance.

The web registrator on [Juliahub.com](http://Juliahub.com) and the GitHub registrator comment-bot have both been patched.

Thanks to Tanmay, Nishanth, and Dilum in helping triage and fix these issues.

---

<div class="post-metadata">

**Author:** ![fonsp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fonsp/32/222349_2.png) [@fonsp](https://discourse.julialang.org/u/fonsp)\
**Post date:** [June 26, 2025, 12:59pm UTC](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189/2 "2025-06-26T12:59:52Z")

</div>

We analysed our HTTP code – we believe that Pluto users are not affected by this CVE, but it is still recommended to `Pkg.update()` as good practice. You don’t need to update Pluto to get the fix, just update the affected packages.

Read more about this here: [Update min HTTP to 1.10.7 by pankgeorg · Pull Request #3277 · fonsp/Pluto.jl · GitHub](https://github.com/fonsp/Pluto.jl/pull/3277#issuecomment-3008405557)

---

<div class="post-metadata">

**Author:** ![avik](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/avik/32/17_2.png) [@avik](https://discourse.julialang.org/u/avik)\
**Post date:** [June 26, 2025, 7:49pm UTC](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189/3 "2025-06-26T19:49:42Z")

</div>

And of course, huge thanks to Jacob Quinn for fixing the HTTP/URI issues so quickly.
