PT-2026-56501 · Guzzle · Guzzle
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Guzzle versions prior to 7.12.3
Description
The
CookieJar component fails to restrict cookies scoped to IP addresses or bare-numeric Domain values to the specific host that issued them. This occurs because the matchesDomain() function applies ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1. This behavior can lead to session fixation, cookie injection, or cross-host cookie disclosure.Recommendations
Update to version 7.12.3.
Exploit
Fix
Session Fixation
Origin Validation Error
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Guzzle