Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2026-59882

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets,...

1 affected package

php-guzzlehttp-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-55766

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and...

1 affected package

php-guzzlehttp-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49214

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an...

1 affected package

php-guzzlehttp-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48998

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server...

1 affected package

php-guzzlehttp-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-29197

Medium priority

Some fixes available 3 of 7

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While...

2 affected packages

php-guzzlehttp-psr7, php-nyholm-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Not affected Not affected Fixed Fixed Not in release
php-nyholm-psr7 Not affected Not affected Fixed Ignored Not in release
Show less packages

CVE-2022-24775

Medium priority

Some fixes available 2 of 5

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4...

1 affected package

php-guzzlehttp-psr7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-guzzlehttp-psr7 Not affected Not affected Fixed Fixed
Show less packages