VYPR
Medium severity4.2OSV Advisory· Published Jul 8, 2026· Updated Jul 17, 2026

CVE-2026-59882

CVE-2026-59882

Description

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
guzzlehttp/psr7Packagist
< 2.12.32.12.3

Affected products

3
  • Guzzle/Psr7OSV3 versions
    2.12.2, 2.12.1, 2.12.0, …+ 2 more
    • (no CPE)range: 2.12.2, 2.12.1, 2.12.0, …
    • (no CPE)range: <2.12.3
    • cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*range: <2.12.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.