{"id":"CVE-2026-67353","aliases":["GHSA-f283-ghqc-fg79"],"url":"https://o3.security/vulnerability/CVE-2026-67353","summary":"guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service","details":"guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.","published":"2026-08-01T12:22:17.339Z","modified":"2026-09-10T03:48:26.043363385Z","cvss":null,"epss":{"score":0.00247,"percentile":0.16051,"asOf":"2026-09-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"guzzlehttp/guzzle","fixedVersion":"7.15.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67353.json"},{"type":"ADVISORY","url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67353"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-service"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:48:26.043363385Z"}}