SCA: security update for guzzlehttp/guzzle (GHSA-v5mv-p594-2x33)

high Tenable Self-Hosted Container Security Plugin ID 445612

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request
URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly
as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen().
libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA
mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the
supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as
127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and
reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who
influences a fetched URI can therefore reach a host the application's checks excluded and read whatever
the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the
transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware
decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build
a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is
fixed in versions 7.15.2 and 8.0.1. (CVE-2026-69246)

Solution

Update the guzzlehttp/guzzle library and its related packages to version 7.15.2 or later.

See Also

https://github.com/advisories/GHSA-v5mv-p594-2x33

Plugin Details

Severity: High

ID: 445612

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/4/2026

Updated: 8/4/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-69246

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/3/2026

Vulnerability Publication Date: 8/3/2026

Reference Information

CVE: CVE-2026-69246