CVE-2026-48998
Description
A flaw was found in guzzlehttp/psr7, a PHP library for HTTP messages. A remote attacker could exploit improper validation of the Host header. By providing a specially crafted Host header, an attacker could cause the system to misinterpret the intended destination. This could lead to requests or credentials being sent to an unintended host, resulting in information disclosure in certain forwarding or gateway configurations.
Statement
This Moderate flaw in guzzlehttp/psr7 allows a remote attacker to provide a malformed Host header, leading to misinterpretation of the intended destination. This can result in information disclosure, particularly in forwarding or gateway configurations where applications rely on the parsed URI host for routing or security decisions and process untrusted HTTP requests.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.