VYPR

apk package

chainguard/privatebin

pkg:apk/chainguard/privatebin

Vulnerabilities (11)

  • CVE-2026-69246HigAug 3, 2026
    affected < 2.0.5-r2fixed 2.0.5-r2

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler

  • CVE-2026-69245MedAug 3, 2026
    affected < 2.0.5-r2fixed 2.0.5-r2

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's

  • CVE-2026-67355MedAug 1, 2026
    affected < 2.0.5-r1fixed 2.0.5-r1

    guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disc

  • CVE-2026-67354MedAug 1, 2026
    affected < 2.0.5-r1fixed 2.0.5-r1

    guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat

  • CVE-2026-67353MedAug 1, 2026
    affected < 2.0.5-r1fixed 2.0.5-r1

    guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data i

  • CVE-2026-67339MedAug 1, 2026
    affected < 2.0.5-r1fixed 2.0.5-r1

    guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that

  • CVE-2026-55767MedJun 23, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string

  • CVE-2026-55766MedJun 23, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attack

  • CVE-2026-55568MedJun 23, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or

  • CVE-2026-49214MedJun 11, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the U

  • CVE-2026-48998MedJun 11, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host he