Guzzlehttp/guzzle
This hub aggregates every CVE we track for Guzzlehttp/guzzle, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
0
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Guzzlehttp/guzzle.
- CVE-2022-31091Change in port should be considered a change in origin in Guzzle7.7
- CVE-2022-31090CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle7.7
- CVE-2022-31042Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle7.5
- CVE-2022-31043Fix failure to strip Authorization header on HTTP downgrade in Guzzle7.5
- CVE-2022-29248Cross-domain cookie leakage in Guzzle8.0
Product normalization is registry-driven with AI assist and human review. How it works