CVE-2026-59883
MEDIUMGuzzle: Cookie Disclosure and Injection via IP-Address Domains
Title source: cnaDescription
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w
X_Refsource_Misc x_refsource_misc
https://github.com/guzzle/guzzle/pull/3694
X_Refsource_Misc x_refsource_misc
https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8
X_Refsource_Misc x_refsource_misc
https://github.com/guzzle/guzzle/releases/tag/7.12.3
Scores
CVSS v3
4.7
EPSS
0.0012
EPSS Percentile
2.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-346
CWE-384
Status
published
Products (3)
guzzle/guzzle
< 7.12.3
guzzlehttp/guzzle
0 - 7.12.3Packagist
guzzlephp/guzzle
< 7.12.3
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026