The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade guzzlehttp/psr7 to version 2.10.2 or higher.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via improper validation of the Host header when parsing raw HTTP request messages or deriving a server request URI from server variables. An attacker can manipulate the Host header to include URI authority delimiters, causing the constructed URI host to differ from the original value, potentially resulting in requests or credentials being sent to an unintended host by exploiting affected forwarding or gateway scenarios.
This vulnerability can be mitigated by validating the Host header as uri-host [ ":" port ] before calling Message::parseRequest() or legacy parse_request() on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo (@), path (/ or \), query (?), fragment (#) delimiters.