Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67353

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 5.3

Описание

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

A flaw was found in guzzlehttp/guzzle. A remote attacker can exploit this vulnerability by sending an excessive number of large 'Set-Cookie' header fields from a malicious server. This causes the application's CookieJar to store an unbounded amount of data in memory, leading to resource exhaustion. The consequence is a Denial of Service (DoS), where the application becomes unresponsive or crashes due to excessive memory consumption and oversized cookie headers.

Отчет

Community packages in Fedora and EPEL that bundle guzzlehttp/guzzle (nextcloud, roundcubemail) already ship patched versions (7.15.2 and 7.15.3 respectively) that include the fix for this vulnerability, and are therefore not affected.

Меры по смягчению последствий

Upgrade guzzlehttp/guzzle to version 7.15.1 or later.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510040guzzlehttp/guzzle: guzzlehttp/guzzle: Denial of Service via unbounded cookie storage

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

CVSS3: 5.3
nvd
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

CVSS3: 5.3
debian
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service v ...

CVSS3: 5.3
github
около 1 месяца назад

Guzzle: Unbounded response cookies risk denial of service

5.3 Medium

CVSS3