Skip to content
Noroxi

guzzlephp records

15 published records for vendor guzzlephp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

15 records
  • Cross-domain cookie leakage in Guzzle

    HighCVSS 8.1No exploitEPSS 1%

    guzzlephp · guzzleMay 25, 2022

  • Improper Input Validation in guzzlehttp/psr7

    HighCVSS 7.5No exploitEPSS 2%

    drupal · drupalMar 21, 2022

  • CURLOPT_HTTPAUTH option not cleared on change of origin in Guzzle

    HighCVSS 7.7No exploitEPSS 2%

    guzzlephp · guzzleJun 27, 2022

  • Fix failure to strip Authorization header on HTTP downgrade in Guzzle

    HighCVSS 7.5No exploitEPSS 2%

    guzzlephp · guzzleJun 9, 2022

  • Failure to strip the Cookie header on change in host or HTTP downgrade in Guzzle

    HighCVSS 7.5No exploitEPSS 2%

    guzzlephp · guzzleJun 9, 2022

  • Change in port should be considered a change in origin in Guzzle

    HighCVSS 7.7No exploitEPSS 2%

    guzzlephp · guzzleJun 27, 2022

  • Improper header name validation in guzzlehttp/psr7

    HighCVSS 7.5No exploitEPSS 1%

    guzzlephp · psr-7Apr 17, 2023

  • Laminas Diactoros vulnerable to HTTP Multiline Header Termination

    MediumCVSS 6.5No exploitEPSS 1%

    getlaminas · laminas-diactorosApr 24, 2023

  • guzzlehttp/psr7: Host Confusion via Weak URI Host Validation

    MediumCVSS 6.5No exploitEPSS 0%

    guzzlephp · psr-7Jul 8, 2026

  • Guzzle: Cookie Disclosure and Injection via IP-Address Domains

    MediumCVSS 6.1No exploitEPSS 0%

    guzzlephp · guzzleJul 8, 2026

  • Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle

    MediumCVSS 5.8No exploitEPSS 0%

    guzzlephp · guzzleJun 23, 2026

  • Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

    MediumCVSS 5.9No exploitEPSS 0%

    guzzlephp · guzzleJun 23, 2026

  • guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

    MediumCVSS 5.3No exploitEPSS 0%

    guzzlephp · psr-7Jun 11, 2026

  • guzzlehttp/psr7 has CRLF Injection via URI Host Component

    MediumCVSS 5.3No exploitEPSS 0%

    guzzlephp · psr-7Jun 11, 2026

  • guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

    MediumCVSS 4.8No exploitEPSS 0%

    guzzlephp · psr-7Jun 23, 2026