guzzlehttp/guzzle Security Advisories for 6.5.1 (14)
-
[HIGH] Guzzle: Noncanonical host can bypass host-based checks
PKSA-gcrk-3vtt-1r14 CVE-2026-69246 GHSA-v5mv-p594-2x33
Affected version: >=8.0.0,<8.0.1|<7.15.2
Reported by:
GitHub -
[MEDIUM] Guzzle: Noncanonical cookie domain keeps subdomain scope
PKSA-cnw1-2ytm-cgr8 CVE-2026-69245 GHSA-f7vp-7xgx-4w4r
Affected version: >=8.0.0,<8.0.1|<7.15.2
Reported by:
GitHub -
[MEDIUM] Guzzle: URI fragments disclosed in redirect Referer headers
PKSA-fy2t-3c5f-827y CVE-2026-67354 GHSA-h95v-h523-3mw8
Affected version: <7.15.1
Reported by:
GitHub -
[MEDIUM] Guzzle: Host-only cookie scope is not preserved
PKSA-qxvb-2bpp-dnk6 CVE-2026-67355 GHSA-wm3w-8rrp-j577
Affected version: <7.15.1
Reported by:
GitHub -
[MEDIUM] Guzzle: Unbounded response cookies risk denial of service
PKSA-bbs6-q5q9-f3t4 CVE-2026-67353 GHSA-f283-ghqc-fg79
Affected version: <7.15.1
Reported by:
GitHub -
[MEDIUM] Guzzle: Cookie Disclosure and Injection via IP-Address Domains
PKSA-bcdd-5xc7-gwfb CVE-2026-59883 GHSA-g446-98w2-8p5w
Affected version: <7.12.3
Reported by:
GitHub -
[MEDIUM] Guzzle: Proxy-Authorization headers can be sent to origin servers
PKSA-pwsk-hy21-4gby CVE-2026-67339 GHSA-94pj-82f3-465w
Affected version: <7.14.2
Reported by:
GitHub -
[MEDIUM] Silent HTTPS proxy downgrade to cleartext
PKSA-k22t-f949-t9g6 CVE-2026-55568 GHSA-wpwq-4j6v-78m3
Affected version: <7.12.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Dot-only cookie domains match all hosts
PKSA-93qv-9n9h-6k6p CVE-2026-55767 GHSA-cwxw-98qj-8qjx
Affected version: <7.12.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CURLOPT_HTTPAUTH option not cleared on change of origin
PKSA-k1b4-kshy-xgbh CVE-2022-31090 GHSA-25mq-v84q-4j7r
Affected version: >=7,<7.4.5|>=4,<6.5.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Change in port should be considered a change in origin
PKSA-yfw5-9gnj-n2c7 CVE-2022-31091 GHSA-q559-8m2m-g699
Affected version: >=7,<7.4.5|>=4,<6.5.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Failure to strip the Cookie header on change in host or HTTP downgrade
PKSA-fvw5-9t6n-nwvr CVE-2022-31042 GHSA-f2wf-25xc-69c9
Affected version: >=7,<7.4.4|>=4,<6.5.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Fix failure to strip Authorization header on HTTP downgrade
PKSA-2z36-j4q9-rsfy CVE-2022-31043 GHSA-w248-ffj2-4v5q
Affected version: >=7,<7.4.4|>=4,<6.5.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Cross-domain cookie leakage
PKSA-6d8m-6kgw-18zr CVE-2022-29248 GHSA-cwmx-hcrq-mhc3
Affected version: >=7,<7.4.3|>=4,<6.5.6
Reported by:
GitHub, FriendsOfPHP/security-advisories