GHSA-32rq-jhr7-m3hhMedium· 5.3▾ SunlitDuplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-94pj-82f3-465w. This link is maintained to preserve external references.
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
guzzlehttp/guzzle < 7.14.2Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-3fvr-2jw6-crq4Medium· 5.3Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client