« Back to list

Guzzlephp

Guzzlephp Guzzle: vulnerabilities and CVEs

Guzzlephp Guzzle has 15 published vulnerabilities, 10 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs15
Last 12 months10
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-69246High (7.2)0.37%—Aug 3, 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as…
CVE-2026-69245Medium (6.5)0.20%—Aug 3, 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP…
CVE-2026-67355High (8.2)0.37%—Aug 1, 2026
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive…
CVE-2026-67354High (8.2)0.37%—Aug 1, 2026
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the…
CVE-2026-67353Medium (6.9)0.42%—Aug 1, 2026
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from…
CVE-2026-67339Medium (6.9)0.37%—Aug 1, 2026
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests…
CVE-2026-59883Medium (6.1)0.17%—Jul 8, 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied…
CVE-2026-55767Medium (5.8)0.21%—Jun 23, 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the…
CVE-2026-55568Medium (5.9)0.15%—Jun 23, 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the…
CVE-2026-32271High (7.7)0.60%—Apr 13, 2026
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated…
CVE-2022-31091High (7.7)1.5%—Jun 27, 2022
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port,…
CVE-2022-31090High (7.7)1.9%—Jun 27, 2022
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an…
CVE-2022-31043High (7.5)1.9%—Jun 10, 2022
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a…
CVE-2022-31042High (7.5)1.9%—Jun 10, 2022
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI…
CVE-2022-29248High (8.1)1.3%—May 25, 2022
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1090.004 Domain Fronting1
  5. T1210 Exploitation of Remote Services1
  6. T1212 Exploitation for Credential Access1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Guzzlephp