Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Guzzlephp

First CVE: Mar 21, 2022Active for: 4 yearsTotal CVEs: 15
30.5
VTI Score
Low

Guzzlephp is a widely embedded HTTP client library for PHP that sits deep in application dependency chains, presenting a supply-chain risk profile despite a narrow product scope. Its vulnerability footprint centers on request-handling and header-processing logic, where weaknesses such as CRLF injection, improper input validation, and inadvertent exposure of sensitive information recur, reflecting the parsing and protocol-compliance demands of an HTTP abstraction layer. Defenders should inventory downstream applications that bundle this library, as remediation often depends on application developers rebuilding rather than on direct patching; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Guzzlephp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2022
4 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59883MEDIUM
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, bec
Jul 8, 20266.130NONO
CVE-2026-59882MEDIUM
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters,
Jul 8, 20266.529NONO
CVE-2026-55568MEDIUM
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Pr
Jun 23, 20265.928NONO
CVE-2026-55767MEDIUM
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesD
Jun 23, 20265.827NONO
CVE-2022-29248HIGH
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie
May 25, 20228.127NONO
CVE-2022-31091HIGH
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a re
Jun 27, 20227.726NONO
CVE-2026-55766MEDIUM
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line field
Jun 23, 20264.825NONO
CVE-2022-31043HIGH
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a serv
Jun 10, 20227.525NONO
CVE-2022-31042HIGH
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server
Jun 10, 20227.525NONO
CVE-2026-49214MEDIUM
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host
Jun 11, 20265.324NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
47%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low3 (20.0%)
High0 (0.0%)
None12 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Guzzlephp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Guzzlephp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Guzzlephp's Products

View all 1 CNAs →

Top CWEs