UBUNTU-CVE-2026-59882
The guzzlehttp/psr7 PHP library prior to version 2.12.3 contains a vulnerability in the Uri::assertValidHost() function. This function fails to reject URI host components that include authority delimiters, embedded ports, or malformed IPv6 brackets. As a result, the Uri::getHost() method may return a host value that differs from the actual URI authority, potentially affecting security or routing decisions. The issue is resolved in version 2.12.3.
AI Analysis
Technical Summary
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.12.3 have a vulnerability where Uri::assertValidHost() does not properly validate the URI host component, allowing malformed hosts with authority delimiters, embedded ports, or incorrect IPv6 bracket usage. This discrepancy causes Uri::getHost() to disagree with the URI authority, which can impact security or routing logic relying on accurate host parsing. The vulnerability is fixed in version 2.12.3.
Potential Impact
This vulnerability may cause applications relying on guzzlehttp/psr7 to incorrectly interpret the host component of a URI, potentially leading to incorrect security or routing decisions. The impact is limited to confidentiality and integrity with low severity, as indicated by the CVSS vector (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N). There are no known exploits in the wild.
Mitigation Recommendations
Upgrade guzzlehttp/psr7 to version 2.12.3 or later, where the Uri::assertValidHost() function properly validates URI host components. No other mitigations are specified. Patch status is confirmed by the vendor advisory stating the fix is in 2.12.3.
UBUNTU-CVE-2026-59882
Description
The guzzlehttp/psr7 PHP library prior to version 2.12.3 contains a vulnerability in the Uri::assertValidHost() function. This function fails to reject URI host components that include authority delimiters, embedded ports, or malformed IPv6 brackets. As a result, the Uri::getHost() method may return a host value that differs from the actual URI authority, potentially affecting security or routing decisions. The issue is resolved in version 2.12.3.
CVSS v3.1
Score 4.2medium
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]+deb10u2build0.20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.12.3 have a vulnerability where Uri::assertValidHost() does not properly validate the URI host component, allowing malformed hosts with authority delimiters, embedded ports, or incorrect IPv6 bracket usage. This discrepancy causes Uri::getHost() to disagree with the URI authority, which can impact security or routing logic relying on accurate host parsing. The vulnerability is fixed in version 2.12.3.
Potential Impact
This vulnerability may cause applications relying on guzzlehttp/psr7 to incorrectly interpret the host component of a URI, potentially leading to incorrect security or routing decisions. The impact is limited to confidentiality and integrity with low severity, as indicated by the CVSS vector (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N). There are no known exploits in the wild.
Mitigation Recommendations
Upgrade guzzlehttp/psr7 to version 2.12.3 or later, where the Uri::assertValidHost() function properly validates URI host components. No other mitigations are specified. Patch status is confirmed by the vendor advisory stating the fix is in 2.12.3.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-59882
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b45468715ace43d6b9a2
Added to database: 07/16/2026, 10:37:08 UTC
Last enriched: 07/16/2026, 11:31:39 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.