Executive brief
Guzzle, a popular PHP library for making web requests, contains a flaw where sensitive proxy login credentials can be accidentally sent to the final destination website instead of staying with the proxy server. This occurs when a request is redirected or bypasses a proxy, potentially allowing a malicious website owner to capture these credentials. An attacker who obtains these credentials could gain unauthorized access to the organization's proxy services or impersonate the user.
Technical details
A vulnerability in Guzzle's cURL and stream handlers causes the 'Proxy-Authorization' header to be incorrectly included in the origin request headers (CURLOPT_HTTPHEADER) rather than being restricted to the proxy-only header list. This occurs when Guzzle's internal route prediction fails to match the actual path taken by libcurl, such as during redirects, SOCKS proxy usage, or when a proxy is bypassed via 'no_proxy' settings. On systems with older libcurl versions (< 7.37.0), the lack of separate proxy header support exacerbates the issue. Attackers controlling an origin server can capture these credentials from incoming request logs. The issue is resolved in version 7.14.2 by ensuring proper header separation and stripping credentials on direct or bypassed routes.
Affected products
- GuzzleHTTP guzzle < 7.14.2
Timeline
- 2026-07-14: patched: Fixed in version 7.14.2
- 2026-07-20: disclosed
References
- https://api.github.com/users/GrahamCampbell
- https://github.com/GrahamCampbell
- https://api.github.com/users/GrahamCampbell/gists%7B/gist_id%7D
- https://api.github.com/users/GrahamCampbell/repos
- https://avatars.githubusercontent.com/u/2829600?v=4
- https://api.github.com/users/GrahamCampbell/events%7B/privacy%7D