Bug 2487892 (CVE-2026-49214)
| Summary: | CVE-2026-49214 guzzlehttp/psr7: `guzzlehttp/psr7`: Request Smuggling and Cache Poisoning via HTTP Header Injection | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in guzzlehttp/psr7, a PHP library for HTTP messages. This vulnerability allows a remote attacker to inject additional HTTP header lines by providing a specially crafted URL that contains ASCII control characters, whitespace, or DEL in the host component. This improper input validation can lead to consequences such as request smuggling or cache poisoning, particularly in environments utilizing HTTP/1.1 connection reuse, proxies, gateways, or load balancers.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2489106, 2489109, 2489110, 2489107, 2489108 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-11 13:01:24 UTC
|