Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…
GHSA-32rq-jhr7-m3hhMedium· 5.3Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-3fvr-2jw6-crq4Medium· 5.3Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved
GHSA-h95v-h523-3mw8Medium· 5.9Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-48998Medium· 5.3guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVE-2026-53723Medium· 5.8guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.