guzzlehttp has 16 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 6 in the 90 before. The busiest recent month was June 2026 with 6. The median CVSS is 5.8 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-201 (5) and CWE-20 (3). Most affected products: guzzlehttp/guzzle (12), guzzlehttp/psr7 (3), guzzlehttp/guzzle-services (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 10 prev 6
Products
- guzzlehttp/guzzle 12
- guzzlehttp/psr7 3
- guzzlehttp/guzzle-services 1
Worst active — by depth score
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client40CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client36GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers32GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved32GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved32
guzzlehttp vulnerabilities
CVEs affecting guzzlehttp, newest first. Open any entry for full detail, references, and exploit status.
16 CVEsRSS
CVE-2026-69245Medium· 6.5Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…
CVE-2026-69246High· 7.2Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…
GHSA-32rq-jhr7-m3hhMedium· 5.3Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-3fvr-2jw6-crq4Medium· 5.3Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
GHSA-f283-ghqc-fg79Medium· 5.3Guzzle: Unbounded response cookies risk denial of service
Guzzle: Unbounded response cookies risk denial of service
GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved
Guzzle: Host-only cookie scope is not preserved
GHSA-h95v-h523-3mw8Medium· 5.9Guzzle: URI fragments disclosed in redirect Referer headers
Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
Guzzle: Proxy-Authorization headers can be sent to origin servers
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
CVE-2026-49214Medium· 5.3guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-48998Medium· 5.3guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVE-2026-53723Medium· 5.8guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator