StackRadar

CVE-2026-59882

Medium

Advisory

Published 21 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
142
of 17,781 indexed, latest versions
Container images
125
deployed by those charts
Fix available
1 of 1
affected package

guzzlehttp/psr7: Host Confusion via Weak URI Host Validation

Carried by container images the latest versions of 142 of 17,781 indexed charts deploy, on 125 images.

Affected packageAffected versionsFixed inImages
guzzlehttp/psr7composer1.4.2, 1.5.2, 1.6.1, 1.7.0+23 more2.12.3125
OSV records
GHSA-c2w2-prh8-qm98

Charts affected

142 by stars
ChartLatestAffected imagesRadar Score
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

8,408
nextcloudcloudve1.13.01 of 2See more

nextcloud cloudve 1.13.0

1 of the 2 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
library/nextcloud:17.0.0-apache96104cb965fc
guzzlehttp/psr7@1.5.2
2.12.3

Open the chart page →

3,016
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
guzzlehttp/psr7@1.9.0
2.12.3

Open the chart page →

2,825
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
guzzlehttp/psr7@1.6.1
2.12.3

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
guzzlehttp/psr7@1.8.1
2.12.3

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

8,408
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
guzzlehttp/psr7@1.8.3
2.12.3

Open the chart page →

5,293
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
cspconsole/csp-control-center:1.0.1046dda4a31bd6
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

12,274
mauticdevtron0.1.31 of 3See more

mautic devtron 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/psr7@1.4.2
2.12.3

Open the chart page →

2,939
mauticdevtron-labs0.1.31 of 3See more

mautic devtron-labs 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/psr7@1.4.2
2.12.3

Open the chart page →

2,939
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
owncloud/server:10.16.3b3f9efdcd7f7
guzzlehttp/psr7@2.8.0
2.12.3

Open the chart page →

10,035
webtreesdjjudas21Verified publisher3.0.01 of 1See more

webtrees djjudas21 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

5,966
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

8,408
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
guzzlehttp/psr7@1.8.5
2.12.3

Open the chart page →

7,255
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
guzzlehttp/psr7@1.8.5
2.12.3

Open the chart page →

7,327
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
guzzlehttp/psr7@2.6.2
2.12.3

Open the chart page →

1,664
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,510
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
guzzlehttp/psr7@2.8.0
2.12.3

Open the chart page →

6,431
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

20,933
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
guzzlehttp/psr7@2.9.0
2.12.3
fireflyiii/data-importer:version-2.2.3ab52bf932546
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

4,829
monicagabe565Verified publisher0.10.01 of 2See more

monica gabe565 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
guzzlehttp/psr7@2.6.2
2.12.3

Open the chart page →

1,173
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
guzzlehttp/psr7@2.4.0
2.12.3

Open the chart page →

4,788
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
guzzlehttp/psr7@2.1.0
2.12.3

Open the chart page →

1,269
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
guzzlehttp/psr7@2.1.0
2.12.3

Open the chart page →

1,043
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
guzzlehttp/psr7@2.9.0
2.12.3

Open the chart page →

9,077
lycheegeek-cookbookVerified publisher6.4.21 of 1See more

lychee geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
lycheeorg/lychee-laravel:v4.3.0308c0e6231da
guzzlehttp/psr7@1.8.1
2.12.3

Open the chart page →

601
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
guzzlehttp/psr7@2.1.0
2.12.3

Open the chart page →

8,392
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

4,358
xbackbonegeek-cookbookVerified publisher5.4.21 of 1See more

xbackbone geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

1,655
glpiglpi-chart0.1.11 of 3See more

glpi glpi-chart 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
guzzlehttp/psr7@2.4.5
2.12.3

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
guzzlehttp/psr7@2.7.0
2.12.3

Open the chart page →

49,025
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,510
cachethelm-charts-nr1.3.51 of 2See more

cachet helm-charts-nr 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/psr7@1.4.2
2.12.3

Open the chart page →

1,896
prometheus-sentry-exporterhelm-charts-nr0.1.51 of 1See more

prometheus-sentry-exporter helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ujamii/prometheus-sentry-exporter:0.5.06243197349e1
guzzlehttp/psr7@1.6.1
2.12.3

Open the chart page →

2,474
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
guzzlehttp/psr7@2.8.0
2.12.3

Open the chart page →

9,342
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/psr7@2.8.0
2.12.3

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/psr7@2.8.0
2.12.3

Open the chart page →

1,136
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,510
sample-appkubeuest0.1.31 of 1See more

sample-app kubeuest 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
michaelepitech/sample-app:latestaf51d61c19f5
guzzlehttp/psr7@2.6.0
2.12.3

Open the chart page →

1,427
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

8,534
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
guzzlehttp/psr7@1.9.1
2.12.3

Open the chart page →

5,332
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,510
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
guzzlehttp/psr7@1.7.0
2.12.3

Open the chart page →

7,492
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
guzzlehttp/psr7@1.8.2
2.12.3

Open the chart page →

7,499
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
guzzlehttp/psr7@2.7.1
2.12.3

Open the chart page →

10,897
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
guzzlehttp/psr7@2.10.4
2.12.3

Open the chart page →

8,303
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59882.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
guzzlehttp/psr7@1.8.5
2.12.3

Open the chart page →

7,327

Container images carrying it

125 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
guzzlehttp/psr7@1.8.5
2.12.3
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
guzzlehttp/psr7@1.7.0
2.12.3
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
guzzlehttp/psr7@1.8.5
2.12.3
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
guzzlehttp/psr7@2.7.0
2.12.3
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
guzzlehttp/psr7@2.1.0
2.12.3
1
ghcr.io/monicahq/monica-next:main8be69156acbb
guzzlehttp/psr7@2.7.1
2.12.3
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
guzzlehttp/psr7@2.9.0
2.12.3
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
guzzlehttp/psr7@1.8.3
2.12.3
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
guzzlehttp/psr7@2.7.0
2.12.3
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
guzzlehttp/psr7@2.6.2
2.12.3
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
guzzlehttp/psr7@1.9.0
2.12.3
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
guzzlehttp/psr7@1.8.3
2.12.3
1
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
guzzlehttp/psr7@2.1.0
2.12.3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
guzzlehttp/psr7@1.7.0
2.12.3
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
guzzlehttp/psr7@1.8.1
2.12.3
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
guzzlehttp/psr7@1.8.1
2.12.3
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
guzzlehttp/psr7@1.8.1
2.12.3
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
guzzlehttp/psr7@2.11.0
2.12.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.