Guzzlephp is a widely embedded HTTP client library for PHP that sits deep in application dependency chains, presenting a supply-chain risk profile despite a narrow product scope. Its vulnerability footprint centers on request-handling and header-processing logic, where weaknesses such as CRLF injection, improper input validation, and inadvertent exposure of sensitive information recur, reflecting the parsing and protocol-compliance demands of an HTTP abstraction layer. Defenders should inventory downstream applications that bundle this library, as remediation often depends on application developers rebuilding rather than on direct patching; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Guzzlephp over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59883MEDIUM Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, bec | Jul 8, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-59882MEDIUM guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, | Jul 8, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-55568MEDIUM Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Pr | Jun 23, 2026 | 5.9 | 28 | NO | NO |
CVE-2026-55767MEDIUM Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesD | Jun 23, 2026 | 5.8 | 27 | NO | NO |
CVE-2022-29248HIGH Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie | May 25, 2022 | 8.1 | 27 | NO | NO |
CVE-2022-31091HIGH Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a re | Jun 27, 2022 | 7.7 | 26 | NO | NO |
CVE-2026-55766MEDIUM guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line field | Jun 23, 2026 | 4.8 | 25 | NO | NO |
CVE-2022-31043HIGH Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a serv | Jun 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-31042HIGH Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server | Jun 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-49214MEDIUM guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host | Jun 11, 2026 | 5.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Guzzlephp.
Media articles that mention a CVE ID that affects a product developed by Guzzlephp — matched by CVE ID, not by vendor name.