Description

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.

Severity (CVSS)

Base score6.9
SeverityMedium
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Affected products

VendorProductVersions
guzzleguzzle0 to <7.14.2; 7.14.2

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 02 Aug 2026 07:05 UTC.