THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67354 (MEDIUM 5.9) — guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat

[NVD] CVE-2026-67354 (MEDIUM 5.9) — guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat

mednvdPublished 2026-08-01

CVE-2026-67354 CVSS: 5.9 MEDIUM Published: 2026-08-01T13:17:06.143

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redir

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67354