Medium severity5.3NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026
CVE-2026-67339
CVE-2026-67339
Description
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
guzzlehttp/guzzlePackagist | < 7.14.2 | 7.14.2 |
Affected products
9- osv-coords8 versionspkg:apk/chainguard/drupal-11.3pkg:apk/chainguard/nextcloud-server-31pkg:apk/chainguard/nextcloud-server-32pkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/privatebinpkg:apk/wolfi/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-33
< 11.3.16-r0+ 7 more
- (no CPE)range: < 11.3.16-r0
- (no CPE)range: < 31.0.14-r5
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 33.0.6-r8
- (no CPE)range: < 34.0.1-r9
- (no CPE)range: < 2.0.5-r1
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 33.0.6-r8
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-94pj-82f3-465wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-67339ghsaADVISORY
- github.com/guzzle/guzzle/commit/9e4580d4b9981e903dc6323fe37f50a96e85b05eghsaWEB
- github.com/guzzle/guzzle/pull/3876ghsaWEB
- github.com/guzzle/guzzle/releases/tag/7.14.2ghsaWEB
- github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465wnvdWEB
- www.vulncheck.com/advisories/guzzlehttp-guzzle-before-proxy-authorization-header-disclosurenvdWEB
News mentions
1- Guzzle: Three August 2026 Vulnerabilities Expose User Data and CredentialsVypr Intelligence · Aug 2, 2026