Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 90%

CVE-2026-48998: CWE-20: Improper Input Validation in guzzle psr7

0
Medium
VulnerabilityCVE-2026-48998cvecve-2026-48998cwe-20cwe-918
Published: 06/11/2026 (06/11/2026, 12:34:32 UTC)
Source: CVE Database V5
Vendor/Project: guzzle
Product: psr7

Description

A vulnerability in guzzlehttp/psr7 versions prior to 2.10.2 allows improper validation of the Host header when parsing raw HTTP requests or deriving server request URIs. Malformed Host headers containing URI authority delimiters can cause the request URI host to differ from the original Host header, potentially leading to incorrect routing or forwarding decisions. The issue is patched in version 2.10.2. Users of legacy 1.x versions should apply workarounds as no patch is available.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected software

Packagistmore threats →ai
guzzle/psr7
pkg:composer/guzzle/psr7
Affected versions
<2.10.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/16/2026, 10:55:44 UTC

Technical Analysis

guzzlehttp/psr7 before 2.10.2 improperly validates the Host header during raw HTTP request parsing and server request URI derivation. Attackers can craft Host headers with URI authority delimiters (e.g., '[email protected]'), causing the constructed URI host to differ from the original Host header value. This discrepancy affects applications that parse attacker-controlled requests or server variables and rely on the URI host for routing, allow-list checks, or forwarding. The vulnerability can lead to requests or credentials being sent to unintended hosts in forwarding or gateway scenarios. The issue is fixed in version 2.10.2. Legacy 1.x versions are unpatched and end-of-life. Workarounds include validating the Host header format before parsing or routing decisions, rejecting Host values containing userinfo, path, query, or fragment delimiters.

Potential Impact

The vulnerability allows an attacker to manipulate the Host header in a way that causes the application to interpret the request URI host differently from the original Host header. This can result in misrouting requests or forwarding credentials to unintended hosts, potentially leading to information disclosure or unauthorized request forwarding. The impact is limited to applications that parse untrusted raw HTTP requests or server variables using affected guzzlehttp/psr7 versions and rely on the URI host for security decisions.

Mitigation Recommendations

A fix is available in guzzlehttp/psr7 version 2.10.2; upgrading to this version or later resolves the issue. For users of legacy 1.x versions, which are end-of-life and unpatched, apply workarounds by validating the Host header to ensure it matches the format 'uri-host[:port]' before parsing requests or making routing/forwarding decisions. Reject Host header values containing userinfo, path, query, or fragment delimiters to prevent exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-26T23:26:07.976Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a2aaf9a57b0f63cf3a75356

Added to database: 06/11/2026, 12:52:42 UTC

Last enriched: 07/16/2026, 10:55:44 UTC

Last updated: 07/31/2026, 19:22:59 UTC

Views: 131

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses