GHSA-q7rv-6hp3-vh96 · Severity: medium · Ecosystem: composer — Improper Input Validation in guzzlehttp/psr7
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.
Conclusion & alert: CVE-2022-24775 is rated Moderate Risk (56.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.93%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-26 | 0.73% | 0.93% | +0.21% |
| 2 | 2026-03-04 | 0.42% | 0.73% | +0.30% |
| 3 | 2026-03-02 | — | 0.42% | — |
Full EPSS history (54 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-q7rv-6hp3-vh96 · Severity: medium · Ecosystem: composer — Improper Input Validation in guzzlehttp/psr7
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-24775 not yet assigned priority: Debian including 1 source packages (php-guzzlehttp-psr7), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2022-24775 |
ubuntu
|
medium | CVE-2022-24775 medium priority: Ubuntu including 1 source packages (php-guzzlehttp-psr7), 13 status rows across 13 suites (focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 5, not-affected 5, released 3. | https://ubuntu.com/security/CVE-2022-24775 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| drupal | drupal | >= 8.0.0, < 9.2.16 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| drupal | drupal | >= 9.3.0, < 9.3.9 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| guzzlephp | psr-7 | < 1.8.4 | cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:* |
| guzzlephp | psr-7 | >= 2.0.0, < 2.1.1 | cpe:2.3:a:guzzlephp:psr-7:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/guzzle/psr7/pull/485/commits/e55afaa3fc138c89adf3b55a8ba20dc60d17f1f1 | Patch Third Party Advisory |
| https://github.com/guzzle/psr7/pull/486/commits/9a96d9db668b485361ed9de7b5bf1e54895df1dc | Patch Third Party Advisory |
| https://github.com/guzzle/psr7/security/advisories/GHSA-q7rv-6hp3-vh96 | Third Party Advisory |
| https://www.drupal.org/sa-core-2022-006 | Patch Third Party Advisory |