Vulnerabilidades em guzzle
22 resultadosAnálise Vexday
Guzzle registra 16 vulnerabilidades históricas, com 8 publicadas nos últimos 90 dias, indicando atividade recente de descoberta; nenhuma está sob ataque ativo conhecido e não há críticas registradas. A fraqueza dominante (CWE-200, divulgação de informações) sugere risco moderado concentrado em exposição de dados, sem urgência crítica no momento.
CVE-2022-24775HIGHImproper Input Validation in guzzlehttp/psr7EPSS 2.4%CVE-2022-31042HIGHFailure to strip the Cookie header on change in host or HTTP downgrade in GuzzleEPSS 1.9%CVE-2022-31043HIGHFix failure to strip Authorization header on HTTP downgrade in GuzzleEPSS 1.9%CVE-2022-31090HIGHCURLOPT_HTTPAUTH option not cleared on change of origin in GuzzleEPSS 1.8%CVE-2022-31091HIGHChange in port should be considered a change in origin in GuzzleEPSS 1.4%CVE-2022-29248HIGHCross-domain cookie leakage in GuzzleEPSS 1.3%CVE-2023-29197MEDIUMImproper header name validation in guzzlehttp/psr7EPSS 1.2%CVE-2025-21617MEDIUMGuzzle OAuth Subscriber has insufficient nonce entropyEPSS 0.5%CVE-2026-67354HIGHguzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via RefererEPSS 0.3%CVE-2026-67353MEDIUMguzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of ServiceEPSS 0.2%CVE-2026-67339MEDIUMguzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header DisclosureEPSS 0.2%CVE-2026-67355HIGHguzzlehttp/guzzle before 7.15.1 Host-only Cookie ScopeEPSS 0.2%CVE-2026-53723MEDIUMguzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA TerminatorEPSS 0.2%CVE-2026-69246HIGHGuzzle: Noncanonical host can bypass host-based checksEPSS 0.2%CVE-2026-48998MEDIUMguzzlehttp/psr7 has Host Confusion via Authority ReinterpretationEPSS 0.2%CVE-2026-49214MEDIUMguzzlehttp/psr7 has CRLF Injection via URI Host ComponentEPSS 0.2%CVE-2026-59882MEDIUMguzzlehttp/psr7: Host Confusion via Weak URI Host ValidationEPSS 0.2%CVE-2026-55766MEDIUMguzzlehttp/psr7: CRLF Injection in HTTP Start-Line SerializationEPSS 0.2%CVE-2026-55767MEDIUMGuzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzleEPSS 0.1%CVE-2026-69245MEDIUMGuzzle: Noncanonical cookie domain keeps subdomain scopeEPSS 0.1%