guzzle
- Total products in the ecosystem
- 4
- Total vulnerabilities (90 days)
- 11
en
Verify to analyze this security profile
As of 09/15/2026, guzzle recorded 11 security vulnerabilities in the last 90 days across 2 products, including 3 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, guzzle had the most security vulnerabilities in the guzzle ecosystem, with 9 vulnerabilities—approximately 81.82% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-69246Guzzle: Noncanonical host can bypass host-based checks | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/03/2026 | SeverityHigh |
CVE-2026-69245Guzzle: Noncanonical cookie domain keeps subdomain scope | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/03/2026 | SeverityMedium |
CVE-2026-67354guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/01/2026 | SeverityHigh |
CVE-2026-67355guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/01/2026 | SeverityHigh |
CVE-2026-67353guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/01/2026 | SeverityMedium |
CVE-2026-67339guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published08/01/2026 | SeverityMedium |
CVE-2026-59883Guzzle: Cookie Disclosure and Injection via IP-Address Domains | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published07/08/2026 | SeverityMedium |
CVE-2026-59882guzzlehttp/psr7: Host Confusion via Weak URI Host Validation | Exploitation statusNot known exploited | FixYes | Affected productpsr7 | Published07/08/2026 | SeverityMedium |
CVE-2026-55766guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization | Exploitation statusNot known exploited | FixYes | Affected productpsr7 | Published06/23/2026 | SeverityMedium |
CVE-2026-55767Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published06/23/2026 | SeverityMedium |
CVE-2026-55568Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext | Exploitation statusNot known exploited | FixYes | Affected productguzzle | Published06/23/2026 | SeverityMedium |
CVE-2026-53723guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle-services | Published06/11/2026 | SeverityMedium |
CVE-2026-49214guzzlehttp/psr7 has CRLF Injection via URI Host Component | Exploitation statusNot known exploited | FixNot confirmed | Affected productpsr7 | Published06/11/2026 | SeverityMedium |
CVE-2026-48998guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation | Exploitation statusNot known exploited | FixNot confirmed | Affected productpsr7 | Published06/11/2026 | SeverityMedium |
CVE-2025-21617Guzzle OAuth Subscriber has insufficient nonce entropy | Exploitation statusNot known exploited | FixYes | Affected productoauth-subscriber | Published01/06/2025 | SeverityMedium |
CVE-2023-29197Improper header name validation in guzzlehttp/psr7 | Exploitation statusNot confirmed | FixYes | Affected productpsr7 | Published04/17/2023 | SeverityMedium |
CVE-2022-31090CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle | Published06/27/2022 | SeverityHigh |
CVE-2022-31091Change in port should be considered a change in origin in Guzzle | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle | Published06/27/2022 | SeverityHigh |
CVE-2022-31043Fix failure to strip Authorization header on HTTP downgrade in Guzzle | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle | Published06/09/2022 | SeverityHigh |
CVE-2022-31042Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle | Published06/09/2022 | SeverityHigh |
CVE-2022-29248Cross-domain cookie leakage in Guzzle | Exploitation statusNot known exploited | FixNot confirmed | Affected productguzzle | Published05/25/2022 | SeverityHigh |
CVE-2022-24775Improper Input Validation in guzzlehttp/psr7 | Exploitation statusNot known exploited | FixYes | Affected productpsr7 | Published03/21/2022 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan