THREAT OPS › Threat News › [NVD] CVE-2026-67354 (MEDIUM 5.9) — guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat
[NVD] CVE-2026-67354 (MEDIUM 5.9) — guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat
CVE-2026-67354 CVSS: 5.9 MEDIUM Published: 2026-08-01T13:17:06.143
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redir
Indicators of compromise
- CVE-2026-67354cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67354