
#CVE-2026-48979 - HTTP/2 request smuggling in #PHP standard library (PSL). Unvalidated #DATA frame bytes allow content overflow. #CVSS 7.5. No patch yet; disable PSL H2 servers or upgrade if fix released. #CVE #infosec #cybersecurity #hosting More: https://www.valtersit.com/cve/CVE-2026-48979
Post summary
The tweet announces CVE‑2026‑48979, an HTTP/2 request smuggling flaw in PHP's standard library, with a CVSS score of 7.5 and no patch yet; users are advised to disable PSL H2 servers or upgrade when a fix arrives.

