Hi Eversign team.
The current version of Guzzle/PSR-7 package dependency is one minor patch behind which has been identified as having a CVE
Dependency:
https://packagist.org/packages/guzzlehttp/psr7
CVE https://www.cve.org/CVERecord?id=CVE-2023-29530
CWE https://cwe.mitre.org/data/definitions/20.html
Snyk: https://security.snyk.io/vuln/SNYK-PHP-GUZZLEHTTPPSR7-5458978
The fix comes in the next minor patch of Guzzle.