VDB

CVE-2026-67355

CVE-2026-67355 PUBLISHED CVSS 8.2 HIGH

Reported by VulnCheck · Published August 1, 2026

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.

Risk Scores

CVSS 4.0
8.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
guzzleguzzle0, 7.15.1
chainguardnextcloud-server-320, 0, 0
guzzleguzzle7.15.1, 0, 7.15.1
chainguardnextcloud-server-310, 0, 0
wolfinextcloud-server-330, 0, 0
chainguarddrupal-11.30, 0, 0
chainguardnextcloud-server-330, 0, 0
chainguardprivatebin0, 0, 0
chainguardnextcloud-server-340, 0, 0
guzzlephpguzzle0, 0
wolfinextcloud-server-320, 0, 0

Timeline

  • Jul 20, 2026 CVE Published
  • Aug 1, 2026 Coalition ESS Score
  • Aug 2, 2026 EPSS Score
  • Aug 3, 2026 Security Advisory
  • Aug 3, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›