CVE-2026-67339

NameCVE-2026-67339
Descriptionguzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
guzzle (PTS)bookworm7.4.5-1vulnerable
trixie7.9.2-0.1vulnerable
forky, sid7.15.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
guzzlesource(unstable)7.14.2-1

Notes

[trixie] - guzzle <no-dsa> (Minor issue)
https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w

Search for package or bug name: Reporting problems