guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. This is a follow-up to CVE-2022-24775 where the fix was incomplete. The issue has been patched in versions 1.9.1 and 2.4.5. There are no known workarounds for this vulnerability. Users are advised to upgrade.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon S3 And Cloudfront Plugin | — | Update amazon-s3-and-cloudfront plugin to version 3.2.2, or a newer patched version | May 15, 2025 | Apr 17, 2023 |
| Debian | — | Upgrade php-guzzlehttp-psr7Upgrade php-nyholm-psr7 | Jan 8, 2024 | Apr 17, 2023 |
| Freebsd | — | Upgrade mediawiki135Upgrade mantis-php81Upgrade mantis-php80Upgrade mantis-php74Upgrade mantis-php83Upgrade mediawiki138Upgrade mantis-php82Upgrade mediawiki139 | Jul 1, 2023 | Jul 1, 2023 |
| Ubuntu | — | Upgrade php-nyholm-psr7 (Ubuntu Pro)Upgrade php-guzzlehttp-psr7Upgrade php-guzzlehttp-psr7 (Ubuntu Pro) | Mar 1, 2024 | Apr 17, 2023 |
| Wp Ses Plugin | — | Update wp-ses plugin to version 1.6.4, or a newer patched version | May 15, 2025 | Apr 17, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub