guzzlephp records
15 published records for vendor guzzlephp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-20 Improper Input Validation4
- CWE-346 Origin Validation Error2
- CWE-436 Interpretation Conflict2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2022-29248No exploit | Cross-domain cookie leakage in Guzzleguzzlephp · guzzle · CWE-200 | High8.1 | — | 1.3% | May 25, 2022 |
31Monitor | CVE-2022-24775No exploit | Improper Input Validation in guzzlehttp/psr7drupal · drupal · CWE-20 | High7.5 | — | 2.5% | Mar 21, 2022 |
31Monitor | CVE-2022-31090No exploit | CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzleguzzlephp · guzzle · CWE-200 | High7.7 | — | 1.9% | Jun 27, 2022 |
31Monitor | CVE-2022-31043No exploit | Fix failure to strip Authorization header on HTTP downgrade in Guzzleguzzlephp · guzzle · CWE-200 | High7.5 | — | 1.9% | Jun 9, 2022 |
31Monitor | CVE-2022-31042No exploit | Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzleguzzlephp · guzzle · CWE-200 | High7.5 | — | 1.9% | Jun 9, 2022 |
30Monitor | CVE-2022-31091No exploit | Change in port should be considered a change in origin in Guzzleguzzlephp · guzzle · CWE-200 | High7.7 | — | 1.5% | Jun 27, 2022 |
30Monitor | CVE-2023-29197No exploit | Improper header name validation in guzzlehttp/psr7guzzlephp · psr-7 · CWE-436 | High7.5 | — | 1.2% | Apr 17, 2023 |
26Monitor | CVE-2023-29530No exploit | Laminas Diactoros vulnerable to HTTP Multiline Header Terminationgetlaminas · laminas-diactoros · CWE-20 | Medium6.5 | — | 1.0% | Apr 24, 2023 |
26Monitor | CVE-2026-59882No exploit | guzzlehttp/psr7: Host Confusion via Weak URI Host Validationguzzlephp · psr-7 · CWE-436 | Medium6.5 | — | 0.3% | Jul 8, 2026 |
24Monitor | CVE-2026-59883No exploit | Guzzle: Cookie Disclosure and Injection via IP-Address Domainsguzzlephp · guzzle · CWE-346 | Medium6.1 | — | 0.2% | Jul 8, 2026 |
23Monitor | CVE-2026-55767No exploit | Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzleguzzlephp · guzzle · CWE-346 | Medium5.8 | — | 0.2% | Jun 23, 2026 |
23Monitor | CVE-2026-55568No exploit | Guzzle: Silent HTTPS-Proxy Downgrade to Cleartextguzzlephp · guzzle · CWE-311 | Medium5.9 | — | 0.1% | Jun 23, 2026 |
21Monitor | CVE-2026-48998No exploit | guzzlehttp/psr7 has Host Confusion via Authority Reinterpretationguzzlephp · psr-7 · CWE-20 | Medium5.3 | — | 0.3% | Jun 11, 2026 |
21Monitor | CVE-2026-49214No exploit | guzzlehttp/psr7 has CRLF Injection via URI Host Componentguzzlephp · psr-7 · CWE-20 | Medium5.3 | — | 0.3% | Jun 11, 2026 |
19Monitor | CVE-2026-55766No exploit | guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serializationguzzlephp · psr-7 · CWE-93 | Medium4.8 | — | 0.2% | Jun 23, 2026 |
- CVE-2022-2924832Monitor
Cross-domain cookie leakage in Guzzle
HighCVSS 8.1No exploitEPSS 1%guzzlephp · guzzleMay 25, 2022
- CVE-2022-2477531Monitor
Improper Input Validation in guzzlehttp/psr7
HighCVSS 7.5No exploitEPSS 2%drupal · drupalMar 21, 2022
- CVE-2022-3109031Monitor
CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle
HighCVSS 7.7No exploitEPSS 2%guzzlephp · guzzleJun 27, 2022
- CVE-2022-3104331Monitor
Fix failure to strip Authorization header on HTTP downgrade in Guzzle
HighCVSS 7.5No exploitEPSS 2%guzzlephp · guzzleJun 9, 2022
- CVE-2022-3104231Monitor
Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle
HighCVSS 7.5No exploitEPSS 2%guzzlephp · guzzleJun 9, 2022
- CVE-2022-3109130Monitor
Change in port should be considered a change in origin in Guzzle
HighCVSS 7.7No exploitEPSS 2%guzzlephp · guzzleJun 27, 2022
- CVE-2023-2919730Monitor
Improper header name validation in guzzlehttp/psr7
HighCVSS 7.5No exploitEPSS 1%guzzlephp · psr-7Apr 17, 2023
- CVE-2023-2953026Monitor
Laminas Diactoros vulnerable to HTTP Multiline Header Termination
MediumCVSS 6.5No exploitEPSS 1%getlaminas · laminas-diactorosApr 24, 2023
- CVE-2026-5988226Monitor
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
MediumCVSS 6.5No exploitEPSS 0%guzzlephp · psr-7Jul 8, 2026
- CVE-2026-5988324Monitor
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
MediumCVSS 6.1No exploitEPSS 0%guzzlephp · guzzleJul 8, 2026
- CVE-2026-5576723Monitor
Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
MediumCVSS 5.8No exploitEPSS 0%guzzlephp · guzzleJun 23, 2026
- CVE-2026-5556823Monitor
Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
MediumCVSS 5.9No exploitEPSS 0%guzzlephp · guzzleJun 23, 2026
- CVE-2026-4899821Monitor
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
MediumCVSS 5.3No exploitEPSS 0%guzzlephp · psr-7Jun 11, 2026
- CVE-2026-4921421Monitor
guzzlehttp/psr7 has CRLF Injection via URI Host Component
MediumCVSS 5.3No exploitEPSS 0%guzzlephp · psr-7Jun 11, 2026
- CVE-2026-5576619Monitor
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
MediumCVSS 4.8No exploitEPSS 0%guzzlephp · psr-7Jun 23, 2026