CVE-2026-59883Medium· 4.7▾ SunlitGuzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix m…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
0.1% → 0.2%
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.
guzzle < 7.12.3Upgrade past the affected range:
guzzle 7.12.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
CVE-2024-23679Critical· 9.8Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue
CVE-2026-59882Medium· 4.2guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP
CVE-2026-92706Low· 3.4Dark Reader is an accessibility browser extension that makes web pages colors dark
CVE-2026-79312Medium· 6.8webpy web.py 0.76 is vulnerable to Session Fixation
CVE-2026-61687High· 7.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale