Known Vulnerabilities for Guzzle by Guzzlephp
Listed below are 7 of the newest known vulnerabilities associated with "Guzzle" by "Guzzlephp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69246 json | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supp... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69245 json | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a coo... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-67355 json | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain fiel... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67354 json | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the opti... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67353 json | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Se... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-67339 json | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL han... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-59883 json | Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-num... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-55791 json | Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-55767 json | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attrib... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55568 json | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS ... | Not Provided | 2026-06-23 | 2026-06-23 |