Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes lea…
Medium CVSS 5.8
Summary
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/guzzle/CVE-2026-55767.yaml
- https://github.com/guzzle/guzzle/commit/7f537cded1912349abf5081258d6db19106d774d
- https://github.com/guzzle/guzzle/pull/3653
- https://github.com/guzzle/guzzle/releases/tag/7.12.1
- https://github.com/guzzle/guzzle/security/advisories/GHSA-cwxw-98qj-8qjx Third Party Advisory
Timeline
- nvd_ingest NVD