Technology · Packagist
guzzlehttp/guzzle (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in guzzlehttp/guzzle (Packagist): 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Guzzle GuzzleHTTP host-only cookie scope disclosure, was published on 1 August 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About guzzlehttp/guzzle (Packagist)
Guzzle is a PHP HTTP client that provides an interface for sending HTTP requests and integrating with web services.
Latest guzzlehttp/guzzle (Packagist) vulnerabilities
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- Guzzle unbounded response cookies denial of service in CookieJarmediumCVSS 5.3
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headerslowCVSS 3.1
- Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of servicelowCVSS 3.1
- Duplicate Advisory: Guzzle: Host-only cookie scope is not preservedlowCVSS 3.1
- Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin serverslowCVSS 3.1
- Guzzle Proxy-Authorization header disclosure to origin serversmediumCVSS 5.3
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- CVE-2026-67353: guzzlehttp Guzzle denial of service in CookieJarmediumCVSS 5.3EPSS 0.4%
- CVE-2026-67339: guzzlehttp Guzzle Proxy-Authorization header disclosuremediumCVSS 5.3EPSS 0.4%
- Guzzle URI fragment disclosure in redirect Referer headersmediumCVSS 5.9
- Guzzle host-only cookie scope disclosure to subdomainsmediumCVSS 5.9
- Guzzle CookieJar unbounded resource allocation denial of servicemediumCVSS 5.3
- Guzzle Proxy-Authorization credential leakage to origin serversmediumCVSS 5.3
- CVE-2026-59883: Guzzle CookieJar cross-host cookie disclosure via IP domain matchingmediumCVSS 4.7EPSS 0.2%
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8EPSS 0.2%
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9EPSS 0.1%
Most severe guzzlehttp/guzzle (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9EPSS 0.1%
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- Guzzle URI fragment disclosure in redirect Referer headersmediumCVSS 5.9
- Guzzle host-only cookie scope disclosure to subdomainsmediumCVSS 5.9
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8EPSS 0.2%
- CVE-2026-67353: guzzlehttp Guzzle denial of service in CookieJarmediumCVSS 5.3EPSS 0.4%
- CVE-2026-67339: guzzlehttp Guzzle Proxy-Authorization header disclosuremediumCVSS 5.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 4 | 0 | |
| 27 Jul 2026 | 12 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/guzzlehttp-guzzle.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "guzzlehttp/guzzle (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/guzzlehttp-guzzle, 26 September 2026.