Host-only Cookie Scope Issue in GuzzleHTTP Guzzle by Guzzle
CVE-2026-67355

8.2HIGH

Key Information:

Vendor

Guzzle

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67355?

The affected versions of GuzzleHTTP Guzzle prior to 7.15.1 contain a flaw that improperly manages host-only cookie scope. This vulnerability allows attackers controlling subdomains to access cookies that are intended solely for the parent domain. By compromising the Domain field during cookie storage, sensitive information such as session identifiers and authorization tokens may be inadvertently disclosed. This poses significant risks, especially when a shared cookie jar crosses trust boundaries, leading to potential session hijacking and unauthorized access across different trust levels.

Affected Version(s)

guzzle 0 < 7.15.1

guzzle 7.15.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GrahamCampbell
.