Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59883

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

A flaw was found in Guzzle, an extensible PHP HTTP client. The CookieJar component improperly handled cookies for IP-address or bare-numeric domains, failing to restrict them to the exact host. This vulnerability could allow a remote attacker to disclose cookies across different hosts, inject malicious cookies, or fixate user sessions, potentially leading to unauthorized access or session hijacking.

Отчет

Red Hat's products are not affected by this flaw because the guzzlehttp/guzzle PHP library is not shipped in any Red Hat product.

Меры по смягчению последствий

Use a separate CookieJar instance per host or trust boundary. Do not store cookies scoped to IP-address or bare-numeric domains in a shared jar.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2498137guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar.

EPSS

Процентиль: 2%
0.00115
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

CVSS3: 4.7
nvd
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.

CVSS3: 4.7
debian
26 дней назад

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar di ...

CVSS3: 4.7
github
14 дней назад

Guzzle: Cookie Disclosure and Injection via IP-Address Domains

EPSS

Процентиль: 2%
0.00115
Низкий

4.7 Medium

CVSS3