Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-67339

2 дня назад

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-67339

2 дня назад

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-32rq-jhr7-m3hh

2 дня назад

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

CVSS3: 5.3
0%
Низкий
2 дня назад
debian логотип
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Prox ...

CVSS3: 5.3
0%
Низкий
2 дня назад
github логотип
GHSA-32rq-jhr7-m3hh

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

CVSS3: 5.3
0%
Низкий
2 дня назад

Уязвимостей на страницу