Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67353

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

EPSS

Процентиль: 16%
0.00247
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
debian
2 дня назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...

CVSS3: 5.3
github
2 дня назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

EPSS

Процентиль: 16%
0.00247
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770