guzzlephp has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 4.5 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
guzzlephp vulnerabilities
CVEs affecting guzzlephp, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-59882Medium· 4.2guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri:…
▾ Sunlitguzzlephp · psr-7EPSS 0.32%via NVD
CVE-2026-59883Medium· 4.7Guzzle is an extensible PHP HTTP client
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix m…
▾ Sunlitguzzlephp · guzzleEPSS 0.17%via NVD