Guzzle
This hub aggregates every CVE we track for Guzzle, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH6
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
6
2024-092026-08
Latest CVEs
The 14 most recently published vulnerabilities affecting Guzzle.
- CVE-2026-69246Guzzle: Noncanonical host can bypass host-based checks7.2
- CVE-2026-69245Guzzle: Noncanonical cookie domain keeps subdomain scope6.5
- CVE-2026-67354guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer5.9
- CVE-2026-67339guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure5.3
- CVE-2026-67355guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope5.9
- CVE-2026-67353guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service5.3
- CVE-2026-59883Guzzle: Cookie Disclosure and Injection via IP-Address Domains4.7
- CVE-2026-55767Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle5.8
- CVE-2026-55568Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext5.9
- CVE-2022-31091Change in port should be considered a change in origin in Guzzle7.7
- CVE-2022-31090CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle7.7
- CVE-2022-31042Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle7.5
- CVE-2022-31043Fix failure to strip Authorization header on HTTP downgrade in Guzzle7.5
- CVE-2022-29248Cross-domain cookie leakage in Guzzle8.0
Product normalization is registry-driven with AI assist and human review. How it works