VendorsGuzzlephpguzzleall versions
Vulnerabilities

Guzzlephp Guzzle

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2022-29248
Cross-domain cookie leakage in Guzzle
Published 2022-05-25 · Modified
8.1EPSS 0.013
CVE-2022-31090
CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle
Published 2022-06-27 · Modified
7.7EPSS 0.019
CVE-2022-31091
Change in port should be considered a change in origin in Guzzle
Published 2022-06-27 · Modified
7.7EPSS 0.015
CVE-2022-31042
Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle
Published 2022-06-09 · Modified
7.5EPSS 0.019
CVE-2022-31043
Fix failure to strip Authorization header on HTTP downgrade in Guzzle
Published 2022-06-09 · Modified
7.5EPSS 0.019
CVE-2026-59883
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-55568
Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Published 2026-06-23 · Analyzed
5.9EPSS 0.001
CVE-2026-55767
Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
Published 2026-06-23 · Modified
5.8EPSS 0.002