{"advisories":{"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-gcrk-3vtt-1r14","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-v5mv-p594-2x33","title":"Guzzle: Noncanonical host can bypass host-based checks","link":"https:\/\/github.com\/advisories\/GHSA-v5mv-p594-2x33","cve":"CVE-2026-69246","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:07:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v5mv-p594-2x33"}]},{"advisoryId":"PKSA-cnw1-2ytm-cgr8","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f7vp-7xgx-4w4r","title":"Guzzle: Noncanonical cookie domain keeps subdomain scope","link":"https:\/\/github.com\/advisories\/GHSA-f7vp-7xgx-4w4r","cve":"CVE-2026-69245","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:05:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7vp-7xgx-4w4r"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":"CVE-2026-67354","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":"CVE-2026-67355","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":"CVE-2026-67353","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-bcdd-5xc7-gwfb","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-g446-98w2-8p5w","title":"Guzzle: Cookie Disclosure and Injection via IP-Address Domains","link":"https:\/\/github.com\/advisories\/GHSA-g446-98w2-8p5w","cve":"CVE-2026-59883","affectedVersions":"\u003C7.12.3","source":"GitHub","reportedAt":"2026-07-20 22:00:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g446-98w2-8p5w"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":"CVE-2026-67339","affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]},{"advisoryId":"PKSA-93qv-9n9h-6k6p","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55767.yaml","title":"Dot-only cookie domains match all hosts","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-cwxw-98qj-8qjx","cve":"CVE-2026-55767","affectedVersions":"\u003C7.12.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-18 14:12:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cwxw-98qj-8qjx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55767.yaml"}]},{"advisoryId":"PKSA-k22t-f949-t9g6","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55568.yaml","title":"Silent HTTPS proxy downgrade to cleartext","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-wpwq-4j6v-78m3","cve":"CVE-2026-55568","affectedVersions":"\u003C7.12.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-18 14:12:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wpwq-4j6v-78m3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55568.yaml"}]},{"advisoryId":"PKSA-yfw5-9gnj-n2c7","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31091.yaml","title":"Change in port should be considered a change in origin","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-q559-8m2m-g699","cve":"CVE-2022-31091","affectedVersions":"\u003E=7,\u003C7.4.5|\u003E=4,\u003C6.5.8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-20 22:16:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q559-8m2m-g699"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31091.yaml"}]},{"advisoryId":"PKSA-k1b4-kshy-xgbh","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31090.yaml","title":"CURLOPT_HTTPAUTH option not cleared on change of origin","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-25mq-v84q-4j7r","cve":"CVE-2022-31090","affectedVersions":"\u003E=7,\u003C7.4.5|\u003E=4,\u003C6.5.8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-20 22:16:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-25mq-v84q-4j7r"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31090.yaml"}]},{"advisoryId":"PKSA-2z36-j4q9-rsfy","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31043.yaml","title":"Fix failure to strip Authorization header on HTTP downgrade","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-w248-ffj2-4v5q","cve":"CVE-2022-31043","affectedVersions":"\u003E=7,\u003C7.4.4|\u003E=4,\u003C6.5.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-09 21:36:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w248-ffj2-4v5q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31043.yaml"}]},{"advisoryId":"PKSA-fvw5-9t6n-nwvr","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31042.yaml","title":"Failure to strip the Cookie header on change in host or HTTP downgrade","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-f2wf-25xc-69c9","cve":"CVE-2022-31042","affectedVersions":"\u003E=7,\u003C7.4.4|\u003E=4,\u003C6.5.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-09 21:36:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f2wf-25xc-69c9"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31042.yaml"}]},{"advisoryId":"PKSA-6d8m-6kgw-18zr","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-29248.yaml","title":"Cross-domain cookie leakage","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-cwmx-hcrq-mhc3","cve":"CVE-2022-29248","affectedVersions":"\u003E=7,\u003C7.4.3|\u003E=4,\u003C6.5.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-05-25 13:19:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cwmx-hcrq-mhc3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-29248.yaml"}]},{"advisoryId":"PKSA-stmn-hvzq-wph6","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2016-5385.yaml","title":"HTTP Proxy header vulnerability","link":"https:\/\/github.com\/guzzle\/guzzle\/releases\/tag\/6.2.1","cve":"CVE-2016-5385","affectedVersions":"\u003E=6,\u003C6.2.1|\u003E=4.0.0-rc2,\u003C4.2.4|\u003E=5,\u003C5.3.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-07-15 17:44:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m6ch-gg5f-wxx3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2016-5385.yaml"}]}]}}