SCA: security update for guzzlehttp/guzzle (GHSA-f7vp-7xgx-4w4r)

medium Tenable Cloud Security Plugin ID 445593

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every
subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP
literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport
reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and
0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps
that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and
127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in
any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1
and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to
evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a
response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the
address, so a server answering for the look-alike name can fix a session or set application state.
Exploitation requires the application to enable cookie support, address an origin by one of these
spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and
8.0.1. (CVE-2026-69245)

Solution

Update the guzzlehttp/guzzle library and its related packages to version 7.15.2 or later.

See Also

https://github.com/advisories/GHSA-f7vp-7xgx-4w4r

Plugin Details

Severity: Medium

ID: 445593

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/4/2026

Updated: 8/4/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-69245

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/3/2026

Vulnerability Publication Date: 8/3/2026

Reference Information

CVE: CVE-2026-69245