CVE-2026-59882
EUVD-2026-4231908.07.2026, 17:17
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| guzzlephp | psr-7 | 𝑥 < 2.12.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration