VYPR

apk package

chainguard/moodle

pkg:apk/chainguard/moodle

Vulnerabilities (2)

  • CVE-2026-69246HigAug 3, 2026
    affected < 5.2.2-r0fixed 5.2.2-r0

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler

  • CVE-2026-69245MedAug 3, 2026
    affected < 5.2.2-r0fixed 5.2.2-r0

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's