guzzle guzzle是guzzle组织的一款用于简化HTTP请求的PHP开发工具。 Guzzle 7.14.2之前版本存在信息泄露漏洞,该漏洞源于cURL处理程序未能正确隔离Proxy-Authorization标头与源服务器,可能导致攻击者在请求被重定向、绕过或通过Guzzle误分类为直接连接的SOCKS代理发送时,通过源服务器访问日志捕获代理凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67354 | 5.9 MEDIUM | guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer |
| CVE-2026-67355 | 5.9 MEDIUM | guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope |
| CVE-2026-67353 | 5.3 MEDIUM | guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service |
No comments yet