guzzlehttp/psr7 vulnerabilities
CVEs whose affected-version data names the guzzlehttp/psr7 package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.23%via GHSA
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/psr7 has CRLF Injection via URI Host Component
▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.19%via GHSA
CVE-2026-48998Medium· 5.3guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.20%via GHSA