CVE-2026-59882
published 2026-07-08CVE-2026-59882: guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.19%
8.4th percentile
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| guzzle | psr7 | < 2.12.3 | 2.12.3 |
| guzzlephp | psr-7 | < 2.12.3 | 2.12.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
bugzilla·2026-07-10·CVSS 4.2
CVE-2026-59882 [MEDIUM] CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Bugzilla
CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
bugzilla·2026-07-10·CVSS 4.2
CVE-2026-59882 [MEDIUM] CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Bugzilla
CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
bugzilla·2026-07-10·CVSS 4.2
CVE-2026-59882 [MEDIUM] CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Bugzilla
CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
bugzilla·2026-07-10·CVSS 4.2
CVE-2026-59882 [MEDIUM] CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
CVE-2026-59882 roundcubemail: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
Bugzilla
CVE-2026-59882 guzzlehttp/psr7: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting
bugzilla·2026-07-08·CVSS 4.2
CVE-2026-59882 [MEDIUM] CVE-2026-59882 guzzlehttp/psr7: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting
CVE-2026-59882 guzzlehttp/psr7: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
2026-07-08
Published