php-standard-library/h2
HTTP/2 binary framing protocol implementation
Activity
- Latest release
- 3mo ago
- Total releases
- 5
- Cadence
- ~5 days
- Last 12 months
- 5
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Mar 19, 2026
| Version | Released | |
|---|---|---|
6.1.2
patch
|
6.1.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
6.2.1
patch
|
6.2.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
6.2.0
minor
1 CVE
CVE-2026-48979
GHSA-pw9p-jvrm-f7rm
Jun 26, 2026
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Impact
A malicious client can:
The vulnerability is only reachable for consumers using Patches
Regression tests landed in #781, 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced. WorkaroundsNone at the protocol layer. Applications using Resources
Affected versions
6.1.0
6.1.1
6.2.0
Fixed in
6.1.2
6.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
6.1.1
patch
1 CVE
CVE-2026-48979
GHSA-pw9p-jvrm-f7rm
Jun 26, 2026
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Impact
A malicious client can:
The vulnerability is only reachable for consumers using Patches
Regression tests landed in #781, 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced. WorkaroundsNone at the protocol layer. Applications using Resources
Affected versions
6.1.0
6.1.1
6.2.0
Fixed in
6.1.2
6.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
6.1.0
initial
1 CVE
CVE-2026-48979
GHSA-pw9p-jvrm-f7rm
Jun 26, 2026
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Impact
A malicious client can:
The vulnerability is only reachable for consumers using Patches
Regression tests landed in #781, 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced. WorkaroundsNone at the protocol layer. Applications using Resources
Affected versions
6.1.0
6.1.1
6.2.0
Fixed in
6.1.2
6.2.1
References
Updated Sep 10, 2026 · Source: OSV.dev |