Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

guzzle — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting guzzle. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Guzzle is a PHP HTTP client library primarily used for making HTTP requests and handling web service interactions. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, often stemming from improper input validation and insecure default configurations. The library's widespread adoption in PHP ecosystems has made it a frequent target for attackers. Notable security characteristics include its complex middleware pipeline, which can introduce vulnerabilities if not properly configured, and several high-severity CVEs have been disclosed over the years, highlighting the importance of keeping Guzzle implementations updated and properly secured.

CVE IDTitleCVSSSeverityPublished
CVE-2026-59883 Guzzle: Cookie Disclosure and Injection via IP-Address Domains — guzzleCWE-346 4.7 Medium2026-07-08
CVE-2026-59882 guzzlehttp/psr7: Host Confusion via Weak URI Host Validation — psr7CWE-436 4.2 Medium2026-07-08
CVE-2026-55766 guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization — psr7CWE-93 4.8 Medium2026-06-23
CVE-2026-55767 Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle — guzzleCWE-346 5.8 Medium2026-06-23
CVE-2026-55568 Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext — guzzleCWE-311 5.9 Medium2026-06-23
CVE-2026-53723 guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator — guzzle-servicesCWE-20 5.8 Medium2026-06-11
CVE-2026-49214 guzzlehttp/psr7 has CRLF Injection via URI Host Component — psr7CWE-20 5.3 Medium2026-06-11
CVE-2026-48998 guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation — psr7CWE-20 5.3 Medium2026-06-11
CVE-2025-21617 Guzzle OAuth Subscriber has insufficient nonce entropy — oauth-subscriberCWE-338 9.1 -2025-01-06
CVE-2023-29197 Improper header name validation in guzzlehttp/psr7 — psr7CWE-436 5.3 Medium2023-04-17
CVE-2022-31090 CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle — guzzleCWE-200 7.7 High2022-06-27
CVE-2022-31091 Change in port should be considered a change in origin in Guzzle — guzzleCWE-200 7.7 High2022-06-27
CVE-2022-31042 Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle — guzzleCWE-200 7.5 High2022-06-09
CVE-2022-31043 Fix failure to strip Authorization header on HTTP downgrade in Guzzle — guzzleCWE-200 7.5 High2022-06-09
CVE-2022-29248 Cross-domain cookie leakage in Guzzle — guzzleCWE-200 8.0 High2022-05-25
CVE-2022-24775 Improper Input Validation in guzzlehttp/psr7 — psr7CWE-20 7.5 High2022-03-21

This page lists every published CVE security advisory associated with guzzle. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.