Denial of Service Vulnerability in GuzzleHTTP by Guzzle, a Product of Guzzle
CVE-2026-67353
6.9MEDIUM
What is CVE-2026-67353?
GuzzleHTTP versions prior to 7.15.1 are susceptible to a denial of service issue stemming from the CookieJar component. This vulnerability permits the acceptance of unlimited Set-Cookie headers without any size limitations. Attackers can exploit this by sending multiple large cookies from a compromised server, leading Guzzle to store an excessive amount of data in memory. This scenario can generate oversized Cookie headers that either fail in application handlers or lead to issues with destination servers, resulting in service disruptions.
Affected Version(s)
guzzle 0 < 7.15.1
guzzle 7.15.1
