PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48979 php-standard-library CVE debrief

The PHP Standard Library (PSL) contains a high-severity vulnerability, CVE-2026-48979, affecting versions 6.1.0, 6.1.1, and 6.2.0. This vulnerability allows for request smuggling due to improper validation of DATA frames in the Psl/H2/Server. A malicious client can exploit this by sending more or fewer DATA bytes than declared, potentially bypassing application-level size limits or causing incorrect behavior in applications that trust the declared length. This issue is fixed in versions 6.1.2 and 6.2.1. The vulnerability is only reachable for consumers using Psl/H2/Server directly to accept untrusted client traffic, while users of documented high-level PSL APIs are not affected.

Vendor
php-standard-library
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-23
Advisory published
2026-06-17
Advisory updated
2026-06-23

Who should care

Developers and administrators using PHP Standard Library (PSL) versions 6.1.0, 6.1.1, or 6.2.0 should be aware of this vulnerability. Specifically, those who directly use Psl/H2/Server to handle untrusted client traffic are at risk. Users of high-level PSL APIs are not affected.

Technical summary

The Psl/H2/Server in PHP Standard Library (PSL) versions 6.1.0, 6.1.1, and 6.2.0 does not properly validate the total bytes received in DATA frames against the content-length header declared in the HEADERS frame. This violates RFC 9113 §8.1.1 and allows for request smuggling. An attacker can exploit this by sending more DATA bytes than declared to smuggle additional content past size limits or send fewer bytes and close the stream early, causing applications that rely on the declared length to behave incorrectly.

Defensive priority

High

Recommended defensive actions

  • Upgrade to PHP Standard Library version 6.1.2 or 6.2.1 immediately.
  • Review and update any applications or services using Psl/H2/Server to handle untrusted client traffic.
  • Implement additional monitoring for unusual traffic patterns that could indicate exploitation attempts.
  • Ensure that applications relying on PSL do not trust declared lengths for DATA frames without proper validation.
  • Consider using documented high-level PSL APIs if not already in use.
  • Review RFC 9113 §8.1.1 for a deeper understanding of the HTTP/2 specification and potential mitigations.

Evidence notes

This vulnerability is confirmed by the CVE record and details from the National Vulnerability Database (NVD). The CVE was published on 2026-06-17 and modified on 2026-06-18. Fixes are available in versions 6.1.2 and 6.2.1 of the PHP Standard Library.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48979 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48979

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48979 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48979

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.