GHSA-3fvr-2jw6-crq4Medium· 5.3▾ SunlitDuplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-f283-ghqc-fg79. This link is maintained to preserve external references.
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
guzzlehttp/guzzle < 7.15.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
GHSA-32rq-jhr7-m3hhMedium· 5.3Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client