guzzlehttp/guzzle vulnerabilities
CVEs whose affected-version data names the guzzlehttp/guzzle package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…
GHSA-32rq-jhr7-m3hhMedium· 5.3Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-3fvr-2jw6-crq4Medium· 5.3Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
Guzzle: Unbounded response cookies risk denial of service
GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved
Guzzle: Host-only cookie scope is not preserved
GHSA-h95v-h523-3mw8Medium· 5.9Guzzle: URI fragments disclosed in redirect Referer headers
Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
Guzzle: Proxy-Authorization headers can be sent to origin servers
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts