guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f283-ghqc-fg79 Guzzle: Unbounded response cookies risk denial of service
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 01 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
Title guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service
First Time appeared Guzzlephp
Guzzlephp guzzle
Weaknesses CWE-770
CPEs cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:*
Vendors & Products Guzzlephp
Guzzlephp guzzle
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-03T18:19:35.276Z

Reserved: 2026-07-29T13:36:36.277Z

Link: CVE-2026-67353

cve-icon Vulnrichment

Updated: 2026-08-03T18:18:37.413Z

cve-icon NVD

Status : Received

Published: 2026-08-01T13:17:06.000

Modified: 2026-08-03T19:16:53.047

Link: CVE-2026-67353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T03:15:03Z

Weaknesses