<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:25:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326587</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326587</link>
      <description>EUVD-2026-326587</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326587</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49214</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49214</link>
      <description>&lt;p&gt;guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49214</guid>
    </item>
    <item>
      <title>GHSA-hq7v-mx3g-29hw — guzzlehttp/psr7 has CRLF Injection via URI Host Component</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hq7v-mx3g-29hw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: guzzlehttp/psr7&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;`guzzlehttp/psr7` did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. The issue requires a PSR-7 request to be serialized into a raw HTTP/1.x message, for example with `GuzzleHttp\Psr7\Message::toString()` or an equivalent custom serializer. Creating a `Uri`, `Request`, or other PSR-7 object alone is not sufficient. The malformed host must be copied into the serialized `Host` header without further validation.&lt;/p&gt;
&lt;p&gt;A vulnerable flow is:&lt;/p&gt;
&lt;p&gt;1. An application accepts a user-controlled URL.
2. The URL is used to construct a PSR-7 `Uri` or `Request`.
3. The host component contains CRLF or another header-unsafe character.
4. The request is serialized into a raw HTTP/1.x message without an explicit `Host` header.
5. The host is copied into the serialized `Host` header.
6. The serialized request is written to the network or otherwise processed by software that does not independently reject the malformed host.&lt;/p&gt;
&lt;p&gt;In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines.&lt;/p&gt;
&lt;p&gt;This is not the normal request-sending path used by `guzzlehttp/guzzle`. Applications using `guzzlehttp/psr7` only through Guzzle&amp;#39;s standard HTTP client APIs are not expected to be affected. Applications are most likely to be affected when they manually serialize PSR-7 requests, forward…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: guzzlehttp/psr7&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;`guzzlehttp/psr7` did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. The issue requires a PSR-7 request to be serialized into a raw HTTP/1.x message, for example with `GuzzleHttp\Psr7\Message::toString()` or an equivalent custom serializer. Creating a `Uri`, `Request`, or other PSR-7 object alone is not sufficient. The malformed host must be copied into the serialized `Host` header without further validation.&lt;/p&gt;
&lt;p&gt;A vulnerable flow is:&lt;/p&gt;
&lt;p&gt;1. An application accepts a user-controlled URL.
2. The URL is used to construct a PSR-7 `Uri` or `Request`.
3. The host component contains CRLF or another header-unsafe character.
4. The request is serialized into a raw HTTP/1.x message without an explicit `Host` header.
5. The host is copied into the serialized `Host` header.
6. The serialized request is written to the network or otherwise processed by software that does not independently reject the malformed host.&lt;/p&gt;
&lt;p&gt;In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines.&lt;/p&gt;
&lt;p&gt;This is not the normal request-sending path used by `guzzlehttp/guzzle`. Applications using `guzzlehttp/psr7` only through Guzzle&amp;#39;s standard HTTP client APIs are not expected to be affected. Applications are most likely to be affected when they manually serialize PSR-7 requests, forward…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hq7v-mx3g-29hw</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49214</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49214</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: php-guzzlehttp-psr7, Ubuntu:20.04:LTS: php-guzzlehttp-psr7, Ubuntu:Pro:22.04:LTS: php-guzzlehttp-psr7, Ubuntu:24.04:LTS: php-guzzlehttp-psr7, Ubuntu:25.10: php-guzzlehttp-psr7, Ubuntu:26.04:LTS: php-guzzlehttp-psr7&lt;/p&gt;
&lt;p&gt;guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: php-guzzlehttp-psr7, Ubuntu:20.04:LTS: php-guzzlehttp-psr7, Ubuntu:Pro:22.04:LTS: php-guzzlehttp-psr7, Ubuntu:24.04:LTS: php-guzzlehttp-psr7, Ubuntu:25.10: php-guzzlehttp-psr7, Ubuntu:26.04:LTS: php-guzzlehttp-psr7&lt;/p&gt;
&lt;p&gt;guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `&amp;#34;\r\nX-Injected: yes&amp;#34;` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49214</guid>
    </item>
  </channel>
</rss>
