Search CVE reports
1 – 6 of 6 results
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets,...
1 affected package
php-guzzlehttp-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and...
1 affected package
php-guzzlehttp-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an...
1 affected package
php-guzzlehttp-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server...
1 affected package
php-guzzlehttp-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
Some fixes available 3 of 7
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While...
2 affected packages
php-guzzlehttp-psr7, php-nyholm-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Not affected | Not affected | Fixed | Fixed | Not in release |
| php-nyholm-psr7 | Not affected | Not affected | Fixed | Ignored | Not in release |
Some fixes available 2 of 5
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4...
1 affected package
php-guzzlehttp-psr7
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| php-guzzlehttp-psr7 | Not affected | Not affected | Fixed | Fixed | — |