There is 1 open security issue in trixie.
1 issue left for the package maintainer to handle:
- CVE-2026-59882:
(needs triaging)
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.
You can find information about how to handle this issue in the security team's documentation.