{"id":"GHSA-pw9p-jvrm-f7rm","summary":"PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling","details":"## Impact\n\n`Psl\\H2\\ServerConnection` does not validate that the total bytes received in DATA frames match the `content-length` header declared in the HEADERS frame, in violation of RFC 9113 §8.1.1.\n\nA malicious client can:\n- Send more DATA bytes than declared, smuggling additional content past application-level size limits.\n- Send fewer DATA bytes than declared and close the stream early, causing applications that trust the declared length to behave incorrectly.\n\nThe vulnerability is only reachable for consumers using `Psl\\H2\\ServerConnection` directly to accept untrusted client traffic. The high-level `Psl\\HTTP\\Server` is in active development and was not yet released at the time of this advisory; consumers of documented high-level PSL APIs are not affected.\n\n## Patches\n\nFixed in [6.1.2](https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2) and [6.2.1](https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1).\n\n- Parses and validates the `content-length` header on incoming HEADERS (server-side only — clients do not enforce this per RFC 9110 §9.3.2).\n- Tracks cumulative DATA frame payload length per stream.\n- Throws `StreamException` on mismatch or overflow.\n\nRegression tests landed in [#781](https://github.com/php-standard-library/php-standard-library/pull/781), 9 of the new tests fail against the pre-fix code, proving the validation boundary is enforced.\n\n## Workarounds\n\nNone at the protocol layer. Applications using `Psl\\H2\\ServerConnection` directly should upgrade.\n\n## Resources\n\n- RFC 9113 §8.1.1 (HTTP/2 request/response exchange)\n- RFC 9110 §8.6 (content-length header)\n- https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2\n- https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1","aliases":["CVE-2026-48979"],"modified":"2026-09-10T03:50:50.162530498Z","published":"2026-06-26T20:55:55Z","database_specific":{"github_reviewed_at":"2026-06-26T20:55:55Z","nvd_published_at":"2026-06-17T21:16:23Z","cwe_ids":["CWE-444"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/php-standard-library/php-standard-library/security/advisories/GHSA-pw9p-jvrm-f7rm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48979"},{"type":"PACKAGE","url":"https://github.com/php-standard-library/php-standard-library"},{"type":"WEB","url":"https://github.com/php-standard-library/php-standard-library/releases/tag/6.1.2"},{"type":"WEB","url":"https://github.com/php-standard-library/php-standard-library/releases/tag/6.2.1"}],"affected":[{"package":{"name":"php-standard-library/h2","ecosystem":"Packagist","purl":"pkg:composer/php-standard-library/h2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.2"}]}],"versions":["6.1.0","6.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pw9p-jvrm-f7rm/GHSA-pw9p-jvrm-f7rm.json"}},{"package":{"name":"php-standard-library/h2","ecosystem":"Packagist","purl":"pkg:composer/php-standard-library/h2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.1"}]}],"versions":["6.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pw9p-jvrm-f7rm/GHSA-pw9p-jvrm-f7rm.json"}},{"package":{"name":"php-standard-library/php-standard-library","ecosystem":"Packagist","purl":"pkg:composer/php-standard-library/php-standard-library"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.2"}]}],"versions":["6.1.0","6.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pw9p-jvrm-f7rm/GHSA-pw9p-jvrm-f7rm.json"}},{"package":{"name":"php-standard-library/php-standard-library","ecosystem":"Packagist","purl":"pkg:composer/php-standard-library/php-standard-library"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.1"}]}],"versions":["6.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pw9p-jvrm-f7rm/GHSA-pw9p-jvrm-f7rm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}