guzzlehttp/psr7
PSR-7 HTTP message library
Activity
- Latest release
- 3w ago
- Total releases
- 71
- Cadence
- ~3 days
- Last 12 months
- 21
Reach
- Stars
- 7.9k
Details
- License
- MIT
- First release
- May 19, 2015
| Version | Released | |
|---|---|---|
3.1.0
minor
|
3.1.0
minor
Dependencies (4)
Changelog
Compare changes
|
|
3.0.1
patch
|
3.0.1
patch
Dependencies (4)
Changelog
Compare changes
|
|
2.13.1
patch
| ||
3.0.0
major
|
3.0.0
major
Dependencies (4)
Changelog
Compare changes
|
|
2.13.0
minor
| ||
2.12.5
patch
| ||
2.12.4
patch
| ||
2.12.3
patch
| ||
2.12.2
patch
1 CVE
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev | ||
2.12.1
patch
1 CVE
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev | ||
2.12.0
minor
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.11.1
patch
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.11.0
minor
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.4
patch
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.3
patch
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.2
patch
2 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.10.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.9.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.9.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.8.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.8.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.7.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.3
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.2
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.6.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.5.0
minor
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.5
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.1
patch
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev |
1.9.1
patch
Dependencies (2)
Changelog
Compare changes
|
|
2.4.4
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.4.3
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.4.2
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.4.1
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.4.0
minor
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
1.9.0
minor
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.3.0
minor
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.2
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.1
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.1.2
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
1.8.5
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.2.0
minor
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.1.1
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
1.8.4
patch
5 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.1.0
minor
6 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-24775
GHSA-q7rv-6hp3-vh96
BIT-drupal-2022-24775
DRUPAL-CORE-2022-006
Mar 25, 2022
Improper Input Validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a carriage return character ( PatchesThe issue is patched in 1.8.4 and 2.1.1. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 11 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
2.0.0
2.1.0
Fixed in
1.8.4
2.1.1
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
1.8.3
patch
6 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-24775
GHSA-q7rv-6hp3-vh96
BIT-drupal-2022-24775
DRUPAL-CORE-2022-006
Mar 25, 2022
Improper Input Validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a carriage return character ( PatchesThe issue is patched in 1.8.4 and 2.1.1. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 11 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
2.0.0
2.1.0
Fixed in
1.8.4
2.1.1
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.0.0
major
6 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-29197
GHSA-wxmh-65f7-jcvw
Apr 19, 2023
Improper header name validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a newline ( PatchesThe issue is patched in 1.9.1 and 2.4.5. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 25 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
1.9.1
2.4.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-24775
GHSA-q7rv-6hp3-vh96
BIT-drupal-2022-24775
DRUPAL-CORE-2022-006
Mar 25, 2022
Improper Input Validation in guzzlehttp/psr7
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactImproper header parsing. An attacker could sneak in a carriage return character ( PatchesThe issue is patched in 1.8.4 and 2.1.1. WorkaroundsThere are no known workarounds. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 11 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
2.0.0
2.1.0
Fixed in
1.8.4
2.1.1
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
2.0.0-rc1
pre
4 CVEs
CVE-2026-59882
GHSA-c2w2-prh8-qm98
Jul 21, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
Impact
You are affected if your application builds a Applications using PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and normalize host values before you build or modify a References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 51 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.12.1
2.12.2
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.3
References
Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-55766
GHSA-vm85-hxw5-5432
Jun 19, 2026
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Impact
Creating or modifying a Applications are most likely to be affected when they manually serialize PSR-7 messages, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, testing, or similar code. Depending on how downstream HTTP/1.1 components parse the serialized message, this may lead to header injection, response splitting, request smuggling, or cache poisoning. PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, reject CR/LF in untrusted method, protocol version, and reason phrase values before constructing or modifying PSR-7 messages. Applications that parse, forward, replay, or serialize raw HTTP messages cannot work around the parser entry points by validating only after parsing. They should validate the raw start line before calling Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 49 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.12.0
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.12.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-48998
GHSA-34xg-wgjx-8xph
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Impact
A vulnerable flow is:
For example, Applications are affected if they parse attacker-controlled raw HTTP requests with PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate Host values before passing untrusted request data to Accept only Do not validate Host by prefixing it with References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49214
GHSA-hq7v-mx3g-29hw
Jun 11, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Impact
A vulnerable flow is:
In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing This is not the normal request-sending path used by PatchesThe issue is patched in WorkaroundsIf you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7
Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. References
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.5.0
+ 43 more Show less
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.0-beta1
2.0.0-rc1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
Fixed in
2.10.2
References Updated Sep 10, 2026 · Source: OSV.dev |