Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67354

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.

A flaw was found in guzzlehttp/guzzle. This vulnerability, located in the RedirectMiddleware, can lead to information disclosure. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from a referring request into the generated Referer header during same-scheme redirects. An attacker controlling the redirect destination can read this fragment, potentially exposing sensitive client data such as one-time login secrets or access tokens. The referer setting is disabled by default.

Отчет

Community packages in Fedora and EPEL that bundle guzzlehttp/guzzle (nextcloud, roundcubemail) already ship patched versions (7.15.2 and 7.15.3 respectively) that include the fix for this vulnerability, and are therefore not affected. Additionally, exploitation requires the non-default allow_redirects.referer setting to be enabled.

Меры по смягчению последствий

Upgrade guzzlehttp/guzzle to version 7.15.1 or later.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2510039guzzlehttp/guzzle: guzzlehttp/guzzle: URI Fragment Disclosure in Referer Header

EPSS

Процентиль: 16%
0.00252
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.

CVSS3: 5.9
nvd
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.

CVSS3: 5.9
debian
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...

CVSS3: 5.9
github
около 1 месяца назад

Guzzle: URI fragments disclosed in redirect Referer headers

EPSS

Процентиль: 16%
0.00252
Низкий

5.9 Medium

CVSS3