Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67355

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.

A flaw was found in guzzlehttp/guzzle. The software does not correctly enforce the "host-only" scope for cookies, which means it stores the request host in the cookie's domain field instead of restricting the cookie to the exact host. This vulnerability could allow an attacker who controls a subdomain (a "child host") to access cookies intended only for the main domain (the "parent host"). Consequently, sensitive information such as user session identifiers or authorization tokens might be disclosed if the same cookie storage is used across different security boundaries.

Отчет

No Red Hat products ship guzzlehttp/guzzle. Community builds of nextcloud and roundcubemail in Fedora and EPEL ship patched versions (7.15.2 and 7.15.3 respectively, fix version is 7.15.1).

Меры по смягчению последствий

Upgrade guzzlehttp/guzzle to version 7.15.1 or later.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-501
https://bugzilla.redhat.com/show_bug.cgi?id=2510020guzzlehttp/guzzle: guzzlehttp/guzzle: Information disclosure from host-only cookie scope issue

EPSS

Процентиль: 14%
0.00229
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.

CVSS3: 5.9
nvd
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.

CVSS3: 5.9
debian
около 1 месяца назад

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...

CVSS3: 5.9
github
около 1 месяца назад

Guzzle: Host-only cookie scope is not preserved

EPSS

Процентиль: 14%
0.00229
Низкий

5.9 Medium

CVSS3