Executive brief
Guzzle is a popular tool used by PHP applications to communicate with other web services. A security flaw in how it handles 'cookies' (small pieces of data used for sessions) allows a malicious website to set a cookie that Guzzle will mistakenly send to other, unrelated websites. This could allow an attacker to perform session fixation or inject unauthorized data into requests sent to trusted services, potentially compromising user accounts or application logic.
Technical details
A vulnerability exists in Guzzle's CookieJar where SetCookie::matchesDomain() incorrectly normalizes dot-only Domain attributes (e.g., 'Domain=.') to an empty string. Because SetCookie::validate() only rejected strictly empty domains, these normalized empty strings were treated as matching any request host. An attacker-controlled server can provide such a cookie, which Guzzle will then include in subsequent requests to unrelated domains if the same CookieJar instance is reused. This enables cookie injection and session fixation attacks. The issue is resolved in version 7.12.1 by rejecting dot-only domains and ensuring empty normalized domains do not match all hosts.
Affected products
- guzzlehttp guzzle < 7.12.1
Timeline
- 2026-06-18: advisory: GitHub Advisory GHSA-cwxw-98qj-8qjx published
- 2026-06-23: disclosed: CVE-2026-55767 published to NVD
- 2026-06-23: patched: Fixed in version 7.12.1