Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wm3w-8rrp-j577 | Guzzle: Host-only cookie scope is not preserved |
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries. | |
| Title | guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope | |
| First Time appeared |
Guzzlephp
Guzzlephp guzzle |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Guzzlephp
Guzzlephp guzzle |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T19:37:29.123Z
Reserved: 2026-07-29T13:36:36.278Z
Link: CVE-2026-67355
Updated: 2026-08-03T19:37:23.975Z
Status : Received
Published: 2026-08-01T13:17:06.283
Modified: 2026-08-03T20:17:27.700
Link: CVE-2026-67355
No data.
OpenCVE Enrichment
Updated: 2026-08-02T03:15:03Z
-
CWE-201
Insertion of Sensitive Information Into Sent Data
Github GHSA