{"id":"CVE-2026-48979","aliases":["GHSA-pw9p-jvrm-f7rm"],"url":"https://o3.security/vulnerability/CVE-2026-48979","summary":"PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling","details":"## Impact\n\n`Psl\\H2\\ServerConnection` does not validate that the total bytes received in DATA frames match the `content-length` header declared in the HEADERS frame, in violation of RFC 9113 §8.1.1.\n\nA malicious client can:\n- Send more DATA bytes than declared, smuggling additional content past application-level size limits.\n- Send fewer DATA bytes than declared and close the stream early, causing applications that trust the declared length to behave incorrectly.\n\nThe vulnerability is only reachable for consumers using `Psl\\H2\\ServerConnection` directly to accept untrusted client traffic. The high-level `Psl\\HTTP\\Server` is in active development and was not yet released at the time of this advisory; consumers of documented high-level PSL APIs are not affected.\n\n## Patches\n\nFixed in [6.1.2](https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2) and [6.2.1](https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1).\n\n- Parses and validates the `content-length` header on incoming HEADERS (server-side only — clients do not enforce this per RFC 9110 §9.3.2).\n- Tracks cumulative DATA frame payload length per stream.\n- Throws `StreamException` on mismatch or overflow.\n\nRegression tests landed in [#781](https://github.com/php-standard-library/php-standard-library/pull/781), 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced.\n\n## Workarounds\n\nNone at the protocol layer. Applications using `Psl\\H2\\ServerConnection` directly should upgrade.\n\n## Resources\n\n- RFC 9113 §8.1.1 (HTTP/2 request/response exchange)\n- RFC 9110 §8.6 (content-length header)\n- https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2\n- https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1","published":"2026-06-17T20:43:25.971Z","modified":"2026-08-12T03:51:15.911460154Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00267,"percentile":0.18795,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"php-standard-library/h2","fixedVersion":"6.1.2"},{"ecosystem":"Packagist","name":"php-standard-library/h2","fixedVersion":"6.2.1"},{"ecosystem":"Packagist","name":"php-standard-library/php-standard-library","fixedVersion":"6.1.2"},{"ecosystem":"Packagist","name":"php-standard-library/php-standard-library","fixedVersion":"6.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2"},{"type":"WEB","url":"https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48979.json"},{"type":"ADVISORY","url":"https://github.com/php-standard-library/php-standard-library/security/advisories/GHSA-pw9p-jvrm-f7rm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48979"},{"type":"PACKAGE","url":"https://github.com/php-standard-library/php-standard-library"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.911460154Z"}}