Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

skovmand's avatar

Any thoughts on the HTTPoxy vulnerability?

Should we take any action when running our apps Forge-provisioned servers? Any thoughts on the problem?

Digital Ocean states that only HTTP and not HTTPS is affected and has a general guide on fixing the vulnerability: https://www.digitalocean.com/community/tutorials/how-to-protect-your-server-against-the-httpoxy-vulnerability

0 likes
8 replies
stefr's avatar

I was just about to post the same question.

1 like
Compers's avatar

I see Guzzle has a patch - but is the framework also at risk (including older versions), or is this purely a vulnerability at the server level?

https://github.com/guzzle/guzzle/releases

This could do with being a cross-post in non-forge related topics

C

1 like
stefr's avatar

Great! Just applied the recipe to all our servers!

2 likes
sidscorner's avatar

If you have a Forge account, log in and click on Recipes on the navigation bar.

Dan's avatar

@Zod You will need to have a Forge account and be logged in, in order to visit that link.

MikeHopley's avatar

I like that I didn't have to lift a finger, and this was patched on my server before I even heard about the vulnerability.

ServerPilot beats Forge, in this respect.

Please or to participate in this conversation.