{"id":"GHSA-v5mv-p594-2x33","summary":"Guzzle: Noncanonical host can bypass host-based checks","details":"### Impact\n\nIn affected versions, Guzzle gives a transport the request URI as text and supplies the `Host` header separately. The cURL handlers set `CURLOPT_URL` to the URI exactly as written and push that `Host` into `CURLOPT_HTTPHEADER`; `StreamHandler` does the same through `fopen()`. libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy `CONNECT`, while the supplied `Host` suppresses the aligned one it would have generated. In `http://127.0.0.%31/` the URI host is one `filter_var()` rejects as an IP literal, yet libcurl decodes it to `127.0.0.1` and reaches loopback with no DNS lookup while the server receives `Host: 127.0.0.%31`.\n\nAn attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever it exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: `no_proxy` selects proxy routing from the literal host, and `RedirectMiddleware` decides from it whether to strip `Authorization` and `Cookie`. The cookie middleware extracts `Set-Cookie` against the URI Guzzle produced, not the authority contacted, so for a raw divergent URI the cookie is stored under the URI host as written. Where Guzzle rewrote that URI but left a divergent `Host`, or where the caller supplied one, the cookie is stored under the canonical name and replayed by ordinary later requests to it. With a third-party `UriInterface`, a host of `blocked.example.com@127.0.0.1` reaches `127.0.0.1` through all three handlers and generates `Authorization: Basic` from userinfo the application never wrote.\n\nExploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. Applications that only fetch URIs they construct themselves are not affected, and an exact allowlist of canonical names ordinarily fails closed; the exposure is to denylists, private-range and IP-literal checks, and any check that treats an unresolvable name as safe. The raw Unicode class needs an IDNA transformation somewhere: either a libcurl built with IDN support or Guzzle's own `idn_conversion`, off by default on both branches, which rewrites the URI in `Client::buildUri()` before a handler sees it and leaves a prebuilt request's explicit `Host` as written, while a request the client builds derives that header from the rewritten URI and produces no divergence. Noncanonical numeric spellings such as `127.1`, `2130706433`, `0x7f000001` and `0177.0.0.1` remain accepted after the patch and reach whatever the transport reads them as, loopback or a routable public host, and the cURL and stream handlers can differ, so a check comparing a host against an address as text stays bypassable. Guzzle does not offer SSRF protection, and neither cache poisoning nor cross-tenant compromise was established.\n\n### Patches\n\nThis is a summary; the patches are the authority. The issue is fixed in `7.15.2` and `8.0.1`, which validate the request host in all three built-in handlers before any network I/O. A URI host is rejected for a byte outside `0x21` to `0x7E`, a percent escape, a URI authority delimiter, unbalanced brackets, or numeric-looking parts followed by a trailing dot. That last rule is deliberately conservative and also refuses out-of-range forms libcurl keeps as names, such as `256.0.0.1.`. An explicit `Host` header must be printable ASCII, and on `7.15.2` free of percent escapes. The client also regenerates a derived `Host` when it rewrites the request URI. Versions before `7.15.2` and version `8.0.0` are affected.\n\n### Workarounds\n\nIf you cannot upgrade, constrain the host yourself before handing a URI to Guzzle, and constrain any explicit `Host` header separately, on every redirect hop. The URI rule assumes `$uri` is a validated `GuzzleHttp\\Psr7\\Uri`, so re-parse a third-party `UriInterface` with `new Uri((string) $uri)` first.\n\n```php\n$host = $uri-\u003egetHost();\n\nif (\n    preg_match('/\\A[\\x21-\\x7E]*\\z/D', $host) !== 1\n    || strpbrk($host, '%@/?#\\\\') !== false\n    || substr($host, -1) === '.'\n) {\n    throw new RuntimeException('Refusing to fetch this URI host.');\n}\n\nif (\n    preg_match('/\\A[\\x21-\\x7E]*\\z/D', $hostHeader) !== 1\n    || strpos($hostHeader, '%') !== false\n) {\n    throw new RuntimeException('Refusing to send this Host header.');\n}\n```\n\nIt differs from the patch in both directions: it refuses `example.com.`, which the patch accepts, and it does not canonicalize `127.1` or `0x7f000001`. Reparsing the URI separates a valid port from the host and rejects malformed bracket forms, so the snippet checks the host component alone. `idn_conversion =\u003e true` is not an access control, since IDNA maps `１２７。０。０。１` onto `127.0.0.1` and direct handler use bypasses it, and `Uri::getHost()` is not an SSRF boundary: it is the host as written, not the host a transport connects to. Where the destination matters, resolve the host and check the addresses, and use a separate cookie jar for untrusted origins.","aliases":["CVE-2026-69246"],"modified":"2026-08-03T21:26:12.210572Z","published":"2026-08-03T21:07:26Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-180","CWE-436","CWE-918","CWE-941"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-03T21:07:26Z"},"references":[{"type":"WEB","url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/pull/3907"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/pull/3908"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf"},{"type":"PACKAGE","url":"https://github.com/guzzle/guzzle"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/releases/tag/7.15.2"},{"type":"WEB","url":"https://github.com/guzzle/guzzle/releases/tag/8.0.1"}],"affected":[{"package":{"name":"guzzlehttp/guzzle","ecosystem":"Packagist","purl":"pkg:composer/guzzlehttp/guzzle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.15.2"}]}],"versions":["4.0.0","4.0.0-rc.1","4.0.0-rc.2","4.0.1","4.0.2","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","5.0.0","5.0.1","5.0.2","5.0.3","5.1.0","5.2.0","5.3.0","5.3.1","5.3.2","5.3.3","5.3.4","6.0.0","6.0.1","6.0.2","6.1.0","6.1.1","6.2.0","6.2.1","6.2.2","6.2.3","6.3.0","6.3.1","6.3.2","6.3.3","6.4.0","6.4.1","6.5.0","6.5.1","6.5.2","6.5.3","6.5.4","6.5.5","6.5.6","6.5.7","6.5.8","7.0.0","7.0.0-beta.1","7.0.0-beta.2","7.0.0-rc.1","7.0.1","7.1.0","7.1.1","7.10.0","7.10.1","7.10.2","7.10.3","7.10.4","7.10.5","7.10.6","7.11.0","7.11.1","7.11.2","7.12.0","7.12.1","7.12.2","7.12.3","7.13.0","7.13.1","7.13.2","7.13.3","7.14.0","7.14.1","7.14.2","7.15.0","7.15.1","7.2.0","7.3.0","7.4.0","7.4.1","7.4.2","7.4.3","7.4.4","7.4.5","7.5.0","7.5.1","7.5.2","7.5.3","7.6.0","7.6.1","7.7.0","7.7.1","7.8.0","7.8.1","7.8.2","7.9.0","7.9.1","7.9.2","7.9.3","v1.0.3","v1.0.4","v2.0.0","v2.0.1","v2.0.2","v2.0.3","v2.0.4","v2.0.5","v2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.2.4","v2.3.2","v2.4.0","v2.4.1","v2.5.0","v2.6.0","v2.6.1","v2.6.2","v2.6.3","v2.6.4","v2.6.5","v2.6.6","v2.7.0","v2.7.1","v2.7.2","v2.8.0","v2.8.1","v2.8.2","v2.8.3","v2.8.4","v2.8.5","v2.8.6","v2.8.7","v2.8.8","v3.0.0","v3.0.1","v3.0.2","v3.0.3","v3.0.4","v3.0.5","v3.0.6","v3.0.7","v3.1.0","v3.1.1","v3.1.2","v3.2.0","v3.3.0","v3.3.1","v3.4.0","v3.4.1","v3.4.2","v3.4.3","v3.5.0","v3.6.0","v3.7.0","v3.7.1","v3.7.2","v3.7.3","v3.7.4","v3.8.0","v3.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-v5mv-p594-2x33/GHSA-v5mv-p594-2x33.json"}},{"package":{"name":"guzzlehttp/guzzle","ecosystem":"Packagist","purl":"pkg:composer/guzzlehttp/guzzle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.1"}]}],"versions":["8.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-v5mv-p594-2x33/GHSA-v5mv-p594-2x33.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}