#1143595 guzzle: CVE-2026-69245 CVE-2026-69246

Package:
src:guzzle
Source:
src:guzzle
Submitter:
Salvatore Bonaccorso
Date:
2026-08-05 05:35:02 UTC
Severity:
normal
Tags:
#1143595#5
Date:
2026-08-04 17:39:23 UTC
From:
To:
Hi,

The following vulnerabilities were published for guzzle.

CVE-2026-69245[0]:
| Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1,
| SetCookie::matchesDomain() gives every subdomain of a cookie Domain
| that cookie unless SetCookie::matchesDomain() recognizes the Domain
| as an IP literal or a numeric host, and the decision comes from the
| domain's own text, so two spellings a transport reads as an address
| keep subdomain scope. Hexadecimal and mixed-base forms such as
| 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0
| reads both as 127.0.0.1. A percent-escaped Domain keeps that scope
| on both branches because percent-decoding sits above numeric
| parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in
| the URI grammar rather than address literals, and no numeric rule in
| any base classifies them, while libcurl decodes the host before
| resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie
| stored for Domain=0x7f000001 is placed in the Cookie header of a
| request to evil.0x7f000001, disclosing a session identifier or token
| to a host that is not that address, and a response from
| evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar
| and replayed to the address, so a server answering for the look-
| alike name can fix a session or set application state. Exploitation
| requires the application to enable cookie support, address an origin
| by one of these spellings, and contact a host whose name ends in
| that spelling. This issue is fixed in versions 7.15.2 and 8.0.1.


CVE-2026-69246[1]:
| Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1,
| Guzzle gives a transport the request URI as text and supplies the
| Host header separately. The cURL handlers set CURLOPT_URL to the URI
| exactly as written and push that Host into CURLOPT_HTTPHEADER;
| StreamHandler does the same through fopen(). libcurl then parses the
| authority itself, percent-decoding it and, on an IDN-capable build,
| applying IDNA mapping, and uses the result to resolve, connect, name
| the TLS peer and address a proxy CONNECT, while the supplied Host
| suppresses the aligned one libcurl would have generated. For a URI
| host written as 127.0.0.%31, filter_var() rejects the host as an IP
| literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback
| with no DNS lookup while the server receives Host: 127.0.0.%31. An
| attacker who influences a fetched URI can therefore reach a host the
| application's checks excluded and read whatever the host exposes of
| the response. The same divergence moves Guzzle's own decisions onto
| a spelling the transport does not use: no_proxy selects proxy
| routing from the literal host, and RedirectMiddleware decides from
| it whether to strip Authorization and Cookie. Exploitation requires
| the application to build a request URI from untrusted input and to
| make a host decision before handing it to Guzzle. This issue is
| fixed in versions 7.15.2 and 8.0.1.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-69245
https://www.cve.org/CVERecord?id=CVE-2026-69245
[1] https://security-tracker.debian.org/tracker/CVE-2026-69246
https://www.cve.org/CVERecord?id=CVE-2026-69246

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143595#12
Date:
2026-08-05 05:33:52 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
guzzle, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143595@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
David Prévot <taffit@debian.org> (supplier of updated guzzle package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 05 Aug 2026 06:56:39 +0200
Source: guzzle
Architecture: source
Version: 7.15.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org>
Changed-By: David Prévot <taffit@debian.org>
Closes: 1143595
Changes:
 guzzle (7.15.2-1) unstable; urgency=medium
 .
   [ Graham Campbell ]
   * Security fixes 7.15 (#3907) (Closes: #1143595)
     + Reject non-printable-ASCII and percent-escaped URI hosts and `Host`
       headers (GHSA-v5mv-p594-2x33) [CVE-2026-69246]
     + Reject request URI hosts that contain a URI authority delimiter
       (GHSA-v5mv-p594-2x33) [CVE-2026-69246]
     + Reject numeric-looking URI hosts with trailing dots, read as IPv4
       addresses (GHSA-v5mv-p594-2x33) [CVE-2026-69246]
     + Treat numeric-in-any-base and percent-escaped cookie domains as
       exact-match-only (GHSA-f7vp-7xgx-4w4r) [CVE-2026-69245]
     + Regenerate a derived `Host` header after client URI rewrites
       (GHSA-v5mv-p594-2x33) [CVE-2026-69246]
 .
   [ David Prévot ]
   * Track version 7 for now
Checksums-Sha1:
 39dcd30674962362a7c90345be78170313a7e16d 1780 guzzle_7.15.2-1.dsc
 7309c992e491d25bada9d358779ffcb7da51fa53 285544 guzzle_7.15.2.orig.tar.xz
 41d73f19a84008f9aaaa4560b0b0cc0eec4a4b5c 6476 guzzle_7.15.2-1.debian.tar.xz
 fd5166c7e0d1278551b970e3f7a2c83105dc8bc0 6352 guzzle_7.15.2-1_amd64.buildinfo
Checksums-Sha256:
 963b028b05a7fca2117b9ba29c92d9682ee43fe0b2c92ee30fc55a359b0f50ad 1780 guzzle_7.15.2-1.dsc
 cb4f59ea2f76b8466b7a193b7c709adbc5a56909c89099aef4c7452f618805e7 285544 guzzle_7.15.2.orig.tar.xz
 8af0932754c2a06cbc09b90cc7001b322cf2fce0a52708efbabad48486457ee3 6476 guzzle_7.15.2-1.debian.tar.xz
 22669ba194cc464ad4ba4f301c8c975e5dafeb3e0431bb0c302b11110c8a283c 6352 guzzle_7.15.2-1_amd64.buildinfo
Files:
 5b3ad8a5080e18468a5ce1302416afbc 1780 php optional guzzle_7.15.2-1.dsc
 35fbec6337bf015d0930c1097cfedcdc 285544 php optional guzzle_7.15.2.orig.tar.xz
 d8370ab9b9ddeed5d1d680a79bc739f4 6476 php optional guzzle_7.15.2-1.debian.tar.xz
 cb3ab8fabbb55e6cf347e6e8700f5f6d 6352 php optional guzzle_7.15.2-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmpyxggSHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08masH/2iTEDNvf1ju345TJN6RBfP1Q35hMbjM
e2uamJNt8FjY8ECiKrxc/2d6in2VmCxkeggwVB6lbZC6W0ZBwt0s4N7o/mBMjZtJ
4tbrvM6HO+abrlEWHqUE0th/P59ZqB6OxxqP3QBG+84B11TGpcOrDUjv0SkQyp3a
dzfIZsxDW7nHBlTd4vj6mq7ZALVwH8T2o6TZt3qHe21Z56E5eTrUGQ+PRhn3SVUu
jHaYdbvnmjlNtuj2N7x0+hqsv+tOzgCkYu7fi17tRwFSv73IOX+cIbQjYqO6IIXR
aqon1wf3reY6lcueGBnA89r0U70Aq9zBDIXrpxbrx4AWreP8bsC5WCo=
=6GRV
-----END PGP SIGNATURE-----