CVE-2026-55766

Description

A flaw was found in guzzlehttp/psr7, a PHP library for HTTP messages. This vulnerability allows a remote attacker to inject arbitrary header lines into serialized HTTP/1.x messages. The flaw stems from the library's failure to reject carriage return (CR) and line feed (LF) characters in HTTP start-line fields. This could lead to information disclosure or manipulation of HTTP headers if an application processes attacker-controlled data in these fields and then serializes the message.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.