THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67353 (MEDIUM 5.3) — guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data i

[NVD] CVE-2026-67353 (MEDIUM 5.3) — guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data i

mednvdPublished 2026-08-01

CVE-2026-67353 CVSS: 5.3 MEDIUM Published: 2026-08-01T13:17:06.000

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67353