guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade php-guzzlehttp-psr7 | Jul 30, 2024 | Mar 21, 2022 |
| Drupal | — | Upgrade to drupal version 9.3.9Upgrade to drupal version 9.2.1 | Mar 23, 2022 | Mar 23, 2022 |
| Insert Special Characters Plugin | — | Update insert-special-characters plugin to version 1.0.5, or a newer patched version | May 15, 2025 | Jul 19, 2022 |
| Ubuntu | — | Upgrade php-guzzlehttp-psr7Upgrade php-guzzlehttp-psr7 (Ubuntu Pro) | Mar 1, 2024 | Mar 21, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub