Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wm3w-8rrp-j577 | Guzzle: Host-only cookie scope is not preserved |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries. | |
| Title | guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope | |
| First Time appeared |
Guzzlephp
Guzzlephp guzzle |
|
| Weaknesses | CWE-201 | |
| CPEs | cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Guzzlephp
Guzzlephp guzzle |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T19:37:29.123Z
Reserved: 2026-07-29T13:36:36.278Z
Link: CVE-2026-67355
Updated: 2026-08-03T19:37:23.975Z
Status : Received
Published: 2026-08-01T13:17:06.283
Modified: 2026-08-03T20:17:27.700
Link: CVE-2026-67355
No data.
OpenCVE Enrichment
Updated: 2026-08-02T03:15:03Z
Github GHSA