Technology · Guzzle
Guzzle vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 11 vulnerabilities in Guzzle: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-69246, was published on 3 August 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About Guzzle
Guzzle is a PHP HTTP client that makes it easy to send HTTP requests and trivial to integrate with web services.
Latest Guzzle vulnerabilities
- CVE-2026-69246: Guzzle noncanonical host bypass in URI handlershighCVSS 7.2EPSS 0.4%
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- Guzzle unbounded response cookies denial of service in CookieJarmediumCVSS 5.3
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- Guzzle Proxy-Authorization header disclosure to origin serversmediumCVSS 5.3
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- Guzzle CookieJar unbounded resource allocation denial of servicemediumCVSS 5.3
- CVE-2026-59883: Guzzle CookieJar cross-host cookie disclosure via IP domain matchingmediumCVSS 4.7EPSS 0.2%
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8EPSS 0.2%
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9
Most severe Guzzle vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69246: Guzzle noncanonical host bypass in URI handlershighCVSS 7.2EPSS 0.4%
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8EPSS 0.2%
- Guzzle unbounded response cookies denial of service in CookieJarmediumCVSS 5.3
- Guzzle Proxy-Authorization header disclosure to origin serversmediumCVSS 5.3
- Guzzle CookieJar unbounded resource allocation denial of servicemediumCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/guzzle.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Guzzle vulnerabilities", https://junglewise.ai/threats/technologies/guzzle, 26 September 2026.