Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59883

Опубликовано: 08 июл. 2026
Источник: debian
EPSS Низкий

Описание

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
guzzlefixed7.12.3-1package
guzzleno-dsatrixiepackage
guzzlepostponedbookwormpackage

Примечания

  • https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w

  • https://github.com/guzzle/guzzle/pull/3694

  • Fixed by: https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8 (7.12.3)

EPSS

Процентиль: 2%
0.00118
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

CVSS3: 4.7
redhat
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

CVSS3: 4.7
nvd
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

CVSS3: 4.7
github
14 дней назад

Guzzle: Cookie Disclosure and Injection via IP-Address Domains

EPSS

Процентиль: 2%
0.00118
Низкий