PT-2026-56500 · Composer · Guzzlehttp/Psr7
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
guzzlehttp/psr7 versions prior to 2.12.3
Description
The
Uri::assertValidHost() function fails to reject URI host components that contain authority delimiters, embedded ports, or malformed IPv6 brackets. This discrepancy allows Uri::getHost() to return a value that differs from the URI authority used for routing or security decisions.Recommendations
Update to version 2.12.3.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Guzzlehttp/Psr7