CVE-2026-49214

NameCVE-2026-49214
Descriptionguzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `"\r\nX-Injected: yes"` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1138265

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-guzzlehttp-psr7 (PTS)bullseye1.7.0-1+deb11u2vulnerable
bookworm2.4.5-1vulnerable
trixie2.7.1-1vulnerable
forky2.11.0-1fixed
sid2.12.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-guzzlehttp-psr7source(unstable)2.10.3-11138265

Notes

[trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
[bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw

Search for package or bug name: Reporting problems