CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:17

Updated : 2026-09-08 20:35


NVD link : CVE-2026-67353

Mitre link : CVE-2026-67353

CVE.ORG link : CVE-2026-67353


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling