Host-only Cookie Scope Issue in GuzzleHTTP Guzzle by Guzzle
CVE-2026-67355
8.2HIGH
What is CVE-2026-67355?
The affected versions of GuzzleHTTP Guzzle prior to 7.15.1 contain a flaw that improperly manages host-only cookie scope. This vulnerability allows attackers controlling subdomains to access cookies that are intended solely for the parent domain. By compromising the Domain field during cookie storage, sensitive information such as session identifiers and authorization tokens may be inadvertently disclosed. This poses significant risks, especially when a shared cookie jar crosses trust boundaries, leading to potential session hijacking and unauthorized access across different trust levels.
Affected Version(s)
guzzle 0 < 7.15.1
guzzle 7.15.1
