Denial of Service Vulnerability in GuzzleHTTP by Guzzle, a Product of Guzzle
CVE-2026-67353

6.9MEDIUM

Key Information:

Vendor

Guzzle

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67353?

GuzzleHTTP versions prior to 7.15.1 are susceptible to a denial of service issue stemming from the CookieJar component. This vulnerability permits the acceptance of unlimited Set-Cookie headers without any size limitations. Attackers can exploit this by sending multiple large cookies from a compromised server, leading Guzzle to store an excessive amount of data in memory. This scenario can generate oversized Cookie headers that either fail in application handlers or lead to issues with destination servers, resulting in service disruptions.

Affected Version(s)

guzzle 0 < 7.15.1

guzzle 7.15.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GrahamCampbell
.