CVE-2026-48998

Description

A flaw was found in guzzlehttp/psr7, a PHP library for HTTP messages. A remote attacker could exploit improper validation of the Host header. By providing a specially crafted Host header, an attacker could cause the system to misinterpret the intended destination. This could lead to requests or credentials being sent to an unintended host, resulting in information disclosure in certain forwarding or gateway configurations.

Statement

This Moderate flaw in guzzlehttp/psr7 allows a remote attacker to provide a malformed Host header, leading to misinterpretation of the intended destination. This can result in information disclosure, particularly in forwarding or gateway configurations where applications rely on the parsed URI host for routing or security decisions and process untrusted HTTP requests.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.