Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fvr-2jw6-crq4

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

EPSS

Процентиль: 16%
0.00247
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
nvd
2 дня назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

CVSS3: 5.3
debian
2 дня назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...

EPSS

Процентиль: 16%
0.00247
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-770