VulnSea

guzzlehttp has 16 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 6 in the 90 before. The busiest recent month was June 2026 with 6. The median CVSS is 5.8 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-201 (5) and CWE-20 (3). Most affected products: guzzlehttp/guzzle (12), guzzlehttp/psr7 (3), guzzlehttp/guzzle-services (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.8
Publish → KEV
Last 90 days
10 prev 6

Products

  • guzzlehttp/guzzle 12
  • guzzlehttp/psr7 3
  • guzzlehttp/guzzle-services 1
16
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

guzzlehttp vulnerabilities

CVEs affecting guzzlehttp, newest first. Open any entry for full detail, references, and exploit status.

16 CVEsRSS

CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.14%via NVD
CVE-2026-69246High· 7.2
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…

Twilightguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via NVD
GHSA-32rq-jhr7-m3hhMedium· 5.3
1mo ago

Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers

Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-3fvr-2jw6-crq4Medium· 5.3
1mo ago

Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service

Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-mqq9-gxg5-m58gHigh· 5.9
1mo ago

Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers

Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers

Twilightguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-mjrx-74jh-7xgwHigh· 5.9
1mo ago

Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved

Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved

Twilightguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-f283-ghqc-fg79Medium· 5.3
2mo ago

Guzzle: Unbounded response cookies risk denial of service

Guzzle: Unbounded response cookies risk denial of service

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-wm3w-8rrp-j577Medium· 5.9
2mo ago

Guzzle: Host-only cookie scope is not preserved

Guzzle: Host-only cookie scope is not preserved

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-h95v-h523-3mw8Medium· 5.9
2mo ago

Guzzle: URI fragments disclosed in redirect Referer headers

Guzzle: URI fragments disclosed in redirect Referer headers

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-94pj-82f3-465wMedium· 5.3
2mo ago

Guzzle: Proxy-Authorization headers can be sent to origin servers

Guzzle: Proxy-Authorization headers can be sent to origin servers

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-55766Medium· 4.8
3mo ago

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.23%via GHSA
CVE-2026-55767Medium· 5.8
3mo ago

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via GHSA
CVE-2026-49214Medium· 5.3
3mo ago

guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 has CRLF Injection via URI Host Component

Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.19%via GHSA
CVE-2026-48998Medium· 5.3
3mo ago

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.20%via GHSA
CVE-2026-53723Medium· 5.8
3mo ago

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

Sunlitguzzlehttp · guzzlehttp/guzzle-servicesEPSS 0.22%via GHSA
guzzlehttp vulnerabilities (CVEs) · VulnSea