CVE-2026-49214: guzzlehttp/psr7 has CRLF Injection via URI Host Component

Published Jun 11, 2026
·
Updated

Impact

guzzlehttp/psr7 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. The issue requires a PSR-7 request to be serialized into a raw HTTP/1.x message, for example with GuzzleHttp\Psr7\Message::toString() or an equivalent custom serializer. Creating a Uri, Request, or other PSR-7 object alone is not sufficient. The malformed host must be copied into the serialized Host header without further validation.

A vulnerable flow is:

1. An application accepts a user-controlled URL. 2. The URL is used to construct a PSR-7 Uri or Request. 3. The host component contains CRLF or another header-unsafe character. 4. The request is serialized into a raw HTTP/1.x message without an explicit Host header. 5. The host is copied into the serialized Host header. 6. The serialized request is written to the network or otherwise processed by software that does not independently reject the malformed host.

In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing "\r\nX-Injected: yes" can cause the generated Host header to span multiple HTTP header lines.

This is not the normal request-sending path used by guzzlehttp/guzzle. Applications using guzzlehttp/psr7 only through Guzzle's standard HTTP client APIs are not expected to be affected. Applications are most likely to be affected when they manually serialize PSR-7 requests, forward raw HTTP messages, or use custom transports, proxying, crawling, webhook delivery, or similar request-dispatch code that serializes requests without independently validating URI hosts and header data. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed serialized request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request.

Patches

The issue is patched in 2.10.2 and later. 1.x is end-of-life and will not receive a patch.

Workarounds

If you cannot upgrade immediately, validate and reject all untrusted URI strings before constructing PSR-7 Uri or Request instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters:

php if (pregmatch('/[\x00-\x20\x7F]/', $untrustedUrl)) { throw new \InvalidArgumentException('Insecure URL detected'); }

Applications that manually serialize or forward requests should also ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network.

References

https://www.rfc-editor.org/rfc/rfc9112.html#section-3.2 https://www.rfc-editor.org/rfc/rfc9112.html#section-5 https://www.rfc-editor.org/rfc/rfc9112.html#section-11.2 https://www.rfc-editor.org/rfc/rfc9110.html#section-7.2

Other sources

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 Uri or Request. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 Host header when no explicit Host header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing "\r\nX-Injected: yes" can cause the generated Host header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in 2.10.2 and later. 1.x is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 Uri or Request instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network.

MITRE

Affected Software

3 affected componentsFixes available
packagist/guzzlehttp/psr7<2.10.2
composer/guzzlehttp/psr7<2.10.2
2.10.2
Guzzlephp Psr-7<2.10.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/guzzlehttp/psr7 to a version that resolves this vulnerability.

    Fixed in 2.10.2
  2. Configuration

    Validate and reject all untrusted URI strings before constructing PSR-7 Uri or Request instances. Reject input containing ASCII control characters, whitespace, or DEL (including CRLF, tab, space, NUL). Example check: if (preg_match('/[\x00-\x20\x7F]/', $untrustedUrl)) { throw new \InvalidArgumentException('Insecure URL detected'); }

    Application input validation reject_untrusted_uri_strings_containing_ASCII_control_whitespace_DEL = true
  3. Compensating control

    Ensure the final HTTP client, transport, or serializer rejects invalid URI and header data before writing requests to the network. Do not rely solely on application-level construction of PSR-7 objects when serializing requests.

  4. Compensating control

    Prefer using guzzlehttp/guzzle's standard HTTP client APIs rather than manually serializing or forwarding PSR-7 requests. Applications that only use Guzzle's standard client APIs are not expected to be affected.

Event History

Jun 11, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·01:04 PM
Data Sourced
via GitHub·01:04 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-49214?

The severity of CVE-2026-49214 is medium with a score of 5.3.

2

How do I fix CVE-2026-49214?

To fix CVE-2026-49214, upgrade guzzlehttp/psr7 to version 2.10.2 or later.

3

What type of vulnerability is CVE-2026-49214?

CVE-2026-49214 is a CRLF Injection vulnerability related to input validation.

4

Which versions of guzzlehttp/psr7 are affected by CVE-2026-49214?

Versions of guzzlehttp/psr7 prior to 2.10.2 are affected by CVE-2026-49214.

5

What can an attacker exploit in CVE-2026-49214?

An attacker can exploit CVE-2026-49214 by injecting ASCII control characters into the URI host components of a user-controlled URL.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203