THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f7vp-7xgx-4w4r (medium) — Guzzle: Noncanonical cookie domain keeps subdomain scope

[GHSA] GHSA-f7vp-7xgx-4w4r (medium) — Guzzle: Noncanonical cookie domain keeps subdomain scope

medgithub_advisoriesPublished 2026-08-03

GHSA-f7vp-7xgx-4w4r Severity: medium CVE: CVE-2026-69245

Guzzle: Noncanonical cookie domain keeps subdomain scope

### Impact

`SetCookie::matchesDomain()` gives every subdomain of a cookie `Domain` that cookie unless it recognizes the `Domain` as an IP literal or a numeric host, and it decides that from the domain's own text, so two spellings a transport reads as an address keep subdomain scope.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f7vp-7xgx-4w4r