Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-59882

29
FAUCET Score

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.

First published: Jul 8, 2026Last modified: Jul 8, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 2.12.3CPE matchmatch criteria
cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.2MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 2nd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: guzzlehttp/psr7Fixed in: 2.12.3
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-c2w2-prh8-qm98medium

guzzlehttp/psr7: Host Confusion via Weak URI Host Validation

Jul 21, 2026

References

github.com / guzzle/psr7/commit/ddd64f17d4cc1f7e5ffe6fd2c989ec7221712580
Patch
github.com / guzzle/psr7/pull/811
Issue TrackingPatch
github.com / guzzle/psr7/releases/tag/2.12.3
ProductRelease Notes
github.com / guzzle/psr7/security/advisories/GHSA-c2w2-prh8-qm98
MitigationVendor Advisory