{"id":"CVE-2026-59883","aliases":["GHSA-g446-98w2-8p5w"],"url":"https://o3.security/vulnerability/CVE-2026-59883","summary":"Guzzle: Cookie Disclosure and Injection via IP-Address Domains","details":"Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.","published":"2026-07-08T15:56:03.689Z","modified":"2026-08-12T03:51:49.250694906Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00167,"percentile":0.06247,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"guzzlehttp/guzzle","fixedVersion":"7.12.3"}],"fix":{"url":"https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8","label":"guzzle/guzzle@b9944c1"},"references":[{"type":"WEB","url":"https://github.com/guzzle/guzzle/releases/tag/7.12.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59883.json"},{"type":"ADVISORY","url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59883"},{"type":"FIX","url":"https://github.com/guzzle/guzzle/commit/b9944c161b12d9ee9c9334cfc5b9659ecd7451f8"},{"type":"FIX","url":"https://github.com/guzzle/guzzle/pull/3694"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:49.250694906Z"}}