Skip to content
RequestGuard Vulnerabilities
Pricing

CVE record

CVE-2026-67353

guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.

CVE evidence

Known exploitation

Not listed in fetched KEV catalog

Absence from the fetched catalog does not establish that exploitation has not occurred.

Severity

moderate

CVSS 6.9 ยท CVSS_V4

Affected packages

1

Supported package records returned by OSV. Vendor and product names are not used to infer matches.

OSV package mapping

Affected open-source packages

PackageEcosystemFixed versions
guzzlehttp/guzzlecomposer7.15.1