guzzlephp
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting guzzlephp.
- CVE-2026-59883Guzzle: Cookie Disclosure and Injection via IP-Address Domains4.7
- CVE-2026-59882guzzlehttp/psr7: Host Confusion via Weak URI Host Validation4.2
- CVE-2026-55766guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization4.8
- CVE-2026-55767Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle5.8
- CVE-2026-55568Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext5.9
- CVE-2026-49214guzzlehttp/psr7 has CRLF Injection via URI Host Component5.3
- CVE-2026-48998guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation5.3
- CVE-2023-29530Laminas Diactoros vulnerable to HTTP Multiline Header Termination7.5
- CVE-2023-29197Improper header name validation in guzzlehttp/psr75.3
- CVE-2022-31091Change in port should be considered a change in origin in Guzzle7.7
- CVE-2022-31090CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle7.7
- CVE-2022-31042Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle7.5
- CVE-2022-31043Fix failure to strip Authorization header on HTTP downgrade in Guzzle7.5
- CVE-2022-29248Cross-domain cookie leakage in Guzzle8.0
- CVE-2022-24775Improper Input Validation in guzzlehttp/psr77.5