CVE-2025-30221 | Shopify pitchfork up to 0.10.x HTTP Response Header response splitting (GHSA-pfqj-w6r6-g86v)
A vulnerability classified as problematic was found in Shopify pitchfork up to 0.10.x. This vulnerability affects unknown code of the component HTTP Response Header Handler. The manipulation leads to http response splitting.
This vulnerability was named CVE-2025-30221. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.