VYPR
Medium severity5.3NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026

CVE-2026-67339

CVE-2026-67339

Description

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
guzzlehttp/guzzlePackagist
< 7.14.27.14.2

Affected products

9

Patches

Vulnerability mechanics

References

7

News mentions

1