CVE-2026-48998: CWE-20: Improper Input Validation in guzzle psr7
A vulnerability in guzzlehttp/psr7 versions prior to 2.10.2 allows improper validation of the Host header when parsing raw HTTP requests or deriving server request URIs. Malformed Host headers containing URI authority delimiters can cause the request URI host to differ from the original Host header, potentially leading to incorrect routing or forwarding decisions. The issue is patched in version 2.10.2. Users of legacy 1.x versions should apply workarounds as no patch is available.
AI Analysis
Technical Summary
guzzlehttp/psr7 before 2.10.2 improperly validates the Host header during raw HTTP request parsing and server request URI derivation. Attackers can craft Host headers with URI authority delimiters (e.g., '[email protected]'), causing the constructed URI host to differ from the original Host header value. This discrepancy affects applications that parse attacker-controlled requests or server variables and rely on the URI host for routing, allow-list checks, or forwarding. The vulnerability can lead to requests or credentials being sent to unintended hosts in forwarding or gateway scenarios. The issue is fixed in version 2.10.2. Legacy 1.x versions are unpatched and end-of-life. Workarounds include validating the Host header format before parsing or routing decisions, rejecting Host values containing userinfo, path, query, or fragment delimiters.
Potential Impact
The vulnerability allows an attacker to manipulate the Host header in a way that causes the application to interpret the request URI host differently from the original Host header. This can result in misrouting requests or forwarding credentials to unintended hosts, potentially leading to information disclosure or unauthorized request forwarding. The impact is limited to applications that parse untrusted raw HTTP requests or server variables using affected guzzlehttp/psr7 versions and rely on the URI host for security decisions.
Mitigation Recommendations
A fix is available in guzzlehttp/psr7 version 2.10.2; upgrading to this version or later resolves the issue. For users of legacy 1.x versions, which are end-of-life and unpatched, apply workarounds by validating the Host header to ensure it matches the format 'uri-host[:port]' before parsing requests or making routing/forwarding decisions. Reject Host header values containing userinfo, path, query, or fragment delimiters to prevent exploitation.
CVE-2026-48998: CWE-20: Improper Input Validation in guzzle psr7
Description
A vulnerability in guzzlehttp/psr7 versions prior to 2.10.2 allows improper validation of the Host header when parsing raw HTTP requests or deriving server request URIs. Malformed Host headers containing URI authority delimiters can cause the request URI host to differ from the original Host header, potentially leading to incorrect routing or forwarding decisions. The issue is patched in version 2.10.2. Users of legacy 1.x versions should apply workarounds as no patch is available.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
guzzlehttp/psr7 before 2.10.2 improperly validates the Host header during raw HTTP request parsing and server request URI derivation. Attackers can craft Host headers with URI authority delimiters (e.g., '[email protected]'), causing the constructed URI host to differ from the original Host header value. This discrepancy affects applications that parse attacker-controlled requests or server variables and rely on the URI host for routing, allow-list checks, or forwarding. The vulnerability can lead to requests or credentials being sent to unintended hosts in forwarding or gateway scenarios. The issue is fixed in version 2.10.2. Legacy 1.x versions are unpatched and end-of-life. Workarounds include validating the Host header format before parsing or routing decisions, rejecting Host values containing userinfo, path, query, or fragment delimiters.
Potential Impact
The vulnerability allows an attacker to manipulate the Host header in a way that causes the application to interpret the request URI host differently from the original Host header. This can result in misrouting requests or forwarding credentials to unintended hosts, potentially leading to information disclosure or unauthorized request forwarding. The impact is limited to applications that parse untrusted raw HTTP requests or server variables using affected guzzlehttp/psr7 versions and rely on the URI host for security decisions.
Mitigation Recommendations
A fix is available in guzzlehttp/psr7 version 2.10.2; upgrading to this version or later resolves the issue. For users of legacy 1.x versions, which are end-of-life and unpatched, apply workarounds by validating the Host header to ensure it matches the format 'uri-host[:port]' before parsing requests or making routing/forwarding decisions. Reject Host header values containing userinfo, path, query, or fragment delimiters to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-26T23:26:07.976Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2aaf9a57b0f63cf3a75356
Added to database: 06/11/2026, 12:52:42 UTC
Last enriched: 07/16/2026, 10:55:44 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 131
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.