← Back

CVE-2023-29197

nvd nist
Published: Apr 17, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. This is a follow-up to CVE-2022-24775 where the fix was incomplete. The issue has been patched in versions 1.9.1 and 2.4.5. There are no known workarounds for this vulnerability. Users are advised to upgrade.

Affected (4)

1 product
Psr 7
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Guzzlephp
Before 1.9.1
From 2.0.0 to 2.4.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 37
Version 38

References (14)

Source: security-advisories@github.com
Not Applicable
Source: security-advisories@github.com
Not Applicable
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description

Timeline

No history available yet.