Skip to main content

Vendor/product archive

guzzlephp / psr-7 CVEs

Beta · best-effort

7 CVEs tagged to guzzlephp / psr-70 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-59882

Published Jul 8, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters,…

CVSS 4.2 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-55766

Published Jun 23, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fiel…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49214

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48998

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29197

Published Apr 17, 2023

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into bot…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24775

Published Mar 21, 2022

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1