This release contains several security fixes in multiple libraries. We advise to update as soon as possible.
react/http
- GHSA-x424-64qh-5j54 A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
- GHSA-g4f2-2pf3-2pwj Unbounded HTTP Client Response Header Buffering Leads to Memory Exhaustion DoS
guzzlehttp/guzzle
- GHSA-v5mv-p594-2x33 Noncanonical host can bypass host-based checks
- GHSA-f7vp-7xgx-4w4r Noncanonical cookie domain keeps subdomain scope
- GHSA-wm3w-8rrp-j577 Host-only cookie scope is not preserved
- GHSA-f283-ghqc-fg79 Unbounded response cookies risk denial of service
- GHSA-h95v-h523-3mw8 URI fragments disclosed in redirect Referer headers
- GHSA-94pj-82f3-465w Proxy-Authorization headers can be sent to origin servers
dompdf/dompdf
- GHSA-cx96-42px-69fm Local file read due to improper file path validation in SVG images encoded as data-URI
- GHSA-wvh6-f5jh-8gw4 Chroot Validation Bypass