Medium severity5.3NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026
CVE-2026-67353
CVE-2026-67353
Description
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
guzzlehttp/guzzlePackagist | < 7.15.1 | 7.15.1 |
Affected products
9- osv-coords8 versionspkg:apk/chainguard/nextcloud-server-32pkg:apk/chainguard/privatebinpkg:apk/chainguard/nextcloud-server-34pkg:apk/wolfi/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-33pkg:apk/chainguard/drupal-11.3pkg:apk/chainguard/nextcloud-server-31pkg:apk/chainguard/nextcloud-server-33
< 32.0.12-r6+ 7 more
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 2.0.5-r1
- (no CPE)range: < 34.0.1-r9
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 33.0.6-r8
- (no CPE)range: < 11.3.16-r0
- (no CPE)range: < 31.0.14-r5
- (no CPE)range: < 33.0.6-r8
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-f283-ghqc-fg79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-67353ghsaADVISORY
- github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4ghsaWEB
- github.com/guzzle/guzzle/pull/3901ghsaWEB
- github.com/guzzle/guzzle/releases/tag/7.15.1ghsaWEB
- github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79nvdWEB
- www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-servicenvdWEB
News mentions
0No linked articles in our index yet.