CVE-2026-67339 PUBLISHED

guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure

Assigner: VulnCheck
Reserved: 29.07.2026 Published: 01.08.2026 Updated: 01.08.2026

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor guzzle
Product guzzle
Versions Default: unaffected
  • affected from 0 to 7.14.2 (excl.)
  • Version 7.14.2 is unaffected

Credits

  • GrahamCampbell reporter

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE