Vendor
Guzzle vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in Guzzle: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-69246, was published on 3 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About Guzzle
Guzzle is a PHP HTTP client that provides an interface for sending HTTP requests and integrating with web services.
Guzzle technologies
- Guzzle11
Latest Guzzle vulnerabilities
- CVE-2026-69246: Guzzle noncanonical host bypass in URI handlershighCVSS 7.2
- Guzzle unbounded response cookies denial of service in CookieJarmediumCVSS 5.3
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- Guzzle Proxy-Authorization header disclosure to origin serversmediumCVSS 5.3
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- Guzzle CookieJar unbounded resource allocation denial of servicemediumCVSS 5.3
- CVE-2026-59883: Guzzle CookieJar cross-host cookie disclosure via IP domain matchingmediumCVSS 4.7EPSS 0.1%
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9
- CVE-2026-53723: Guzzle Guzzle Services XML injection in request serializermediumCVSS 5.8
- CVE-2025-21617: Guzzle OAuth Subscriber weak PRNG in nonce generationmediumCVSS 6.3EPSS 0.4%
Most severe Guzzle vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69246: Guzzle noncanonical host bypass in URI handlershighCVSS 7.2
- CVE-2025-21617: Guzzle OAuth Subscriber weak PRNG in nonce generationmediumCVSS 6.3EPSS 0.4%
- CVE-2026-67355: Guzzle host-only cookie scope not preservedmediumCVSS 5.9EPSS 0.4%
- CVE-2026-67354: Guzzle URI fragment disclosure in redirect Referer headermediumCVSS 5.9EPSS 0.4%
- Guzzle information disclosure in RedirectMiddleware Referer headersmediumCVSS 5.9
- Guzzle GuzzleHTTP host-only cookie scope disclosuremediumCVSS 5.9
- CVE-2026-55568: Guzzle silent HTTPS proxy downgrade to cleartextmediumCVSS 5.9
- CVE-2026-55767: Guzzle CookieJar improper domain validation allows cookie injectionmediumCVSS 5.8
- CVE-2026-53723: Guzzle Guzzle Services XML injection in request serializermediumCVSS 5.8
- Guzzle unbounded response cookies denial of service in CookieJarmediumCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/guzzle.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Guzzle vulnerabilities", https://junglewise.ai/threats/vendors/guzzle, 26 September 2026.