guzzlehttp/guzzle
Packagist15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting guzzlehttp/guzzlepage 1 of 1
- CVE-2016-5385HIGHCVSS 8.1EG 8.4✓ Fixed in 5.3.12016-07-19
vulnerable: 5.0.0 ... 5.3.0 (7 versions)
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remo…
- CVE-2022-29248HIGHCVSS 8.0EG 8.0✓ Fixed in 7.4.32022-05-25
vulnerable: 7.0.0 ... 7.4.2 (9 versions)
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cook…
- CVE-2022-31042HIGHCVSS 7.5EG 7.5✓ Fixed in 7.4.42022-06-10
vulnerable: 7.0.0 ... 7.4.3 (10 versions)
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` sch…
- CVE-2022-31043HIGHCVSS 7.5EG 7.5✓ Fixed in 7.4.42022-06-10
vulnerable: 7.0.0 ... 7.4.3 (10 versions)
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` …
- CVE-2022-31090HIGHCVSS 7.7EG 7.7✓ Fixed in 7.4.52022-06-27
vulnerable: 7.0.0 ... 7.4.4 (11 versions)
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` heade…
- CVE-2022-31091HIGHCVSS 7.7EG 7.7✓ Fixed in 7.4.52022-06-27
vulnerable: 7.0.0 ... 7.4.4 (11 versions)
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to foll…
- CVE-2026-55568MEDIUMCVSS 5.9EG 5.9✓ Fixed in 7.12.12026-06-19
vulnerable: 4.0.0 ... v3.8.1 (163 versions)
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization hea…
- CVE-2026-55767MEDIUMCVSS 5.8EG 5.8✓ Fixed in 7.12.12026-06-19
vulnerable: 4.0.0 ... v3.8.1 (163 versions)
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normal…
- CVE-2026-59883MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.12.32026-07-08
vulnerable: 4.0.0 ... v3.8.1 (165 versions)
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix mat…
- CVE-2026-67339MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.14.22026-08-01
vulnerable: 4.0.0 ... v3.8.1 (172 versions)
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, byp…
- CVE-2026-67353MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.15.12026-08-01
vulnerable: 4.0.0 ... v3.8.1 (174 versions)
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server,…
- CVE-2026-67354MEDIUMCVSS 5.9EG 5.9✓ Fixed in 7.15.12026-08-01
vulnerable: 4.0.0 ... v3.8.1 (174 versions)
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') fr…
- CVE-2026-67355MEDIUMCVSS 5.9EG 5.9✓ Fixed in 7.15.12026-08-01
vulnerable: 4.0.0 ... v3.8.1 (174 versions)
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intende…
- CVE-2026-69245MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.0.12026-08-03
vulnerable: 8.0.0
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host,…
- CVE-2026-69246HIGHCVSS 7.2EG 7.2✓ Fixed in 8.0.12026-08-03
vulnerable: 8.0.0
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Hos…
Check whether guzzlehttp/guzzle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for guzzlehttp/guzzle CVEs against the assets you own.
Start Free Scan →