{"id":"CVE-2026-67355","aliases":["GHSA-wm3w-8rrp-j577"],"url":"https://o3.security/vulnerability/CVE-2026-67355","summary":"guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope","details":"guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries.","published":"2026-08-01T12:22:17.646Z","modified":"2026-09-10T03:48:31.096926365Z","cvss":null,"epss":{"score":0.00229,"percentile":0.13829,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"guzzlehttp/guzzle","fixedVersion":"7.15.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67355.json"},{"type":"ADVISORY","url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67355"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scope"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:48:31.096926365Z"}}