CVE-2026-48979
php-standard-library php-standard-library, php-standard-library/h2
PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, allowing request smuggling. This is in violation of RFC 9113 §8.1.1. A malicious client is able to send more DATA bytes than declared, smuggling additional content past application-level size limits and send fewer DATA bytes than declared and close the stream early, causing applications...
- CVSS
- 7.5
- EPSS
- 0.27% 18.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18