GHSA-v5mv-p594-2x33 (CVE-2026-69246, high) - a noncanonical host can bypass host-based checks. GHSA-f7vp-7xgx-4w4r (CVE-2026-69245, medium) - a noncanonical cookie domain keeps subdomain scope. Both affect
=8.0.0,<8.0.1 on the 8.x line.
No constraint change is needed: core/composer.json already allows ^8.0. 8.0.1 is the minimal fixed release; guzzlehttp/promises and guzzlehttp/psr7 are unchanged, and no metapackage pins guzzle.
Closes #3619764