Medium severity5.9NVD Advisory· Published Aug 1, 2026· Updated Sep 8, 2026
CVE-2026-67355
CVE-2026-67355
Description
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
guzzlehttp/guzzlePackagist | < 7.15.1 | 7.15.1 |
Affected products
8- osv-coords7 versionspkg:apk/chainguard/drupal-11.3pkg:apk/chainguard/nextcloud-server-32pkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/privatebinpkg:apk/wolfi/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-33
< 11.3.16-r0+ 6 more
- (no CPE)range: < 11.3.16-r0
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 33.0.6-r8
- (no CPE)range: < 34.0.1-r9
- (no CPE)range: < 2.0.5-r1
- (no CPE)range: < 32.0.12-r6
- (no CPE)range: < 33.0.6-r8
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-wm3w-8rrp-j577ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-67355ghsaADVISORY
- github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4ghsaWEB
- github.com/guzzle/guzzle/pull/3901ghsaWEB
- github.com/guzzle/guzzle/releases/tag/7.15.1ghsaWEB
- github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577nvdWEB
- www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scopenvdWEB
News mentions
1- Guzzle: Three August 2026 Vulnerabilities Expose User Data and CredentialsVypr Intelligence · Aug 2, 2026