GHSA-v5mv-p594-2x33 (CVE-2026-69246, high) - a noncanonical host can bypass host-based checks. GHSA-f7vp-7xgx-4w4r (CVE-2026-69245, medium) - a noncanonical cookie domain keeps subdomain scope. Both affect <7.15.2 on the 7.x line; 11.x locked 7.12.1.
guzzlehttp/promises and guzzlehttp/psr7 move with it because 7.15.5 requires ^2.5.3 and ^2.13.1 respectively. No constraint change is needed: core/composer.json already allows ^7.10.
Closes #3619764