THREAT OPS › Threat News › [GHSA] GHSA-f7vp-7xgx-4w4r (medium) — Guzzle: Noncanonical cookie domain keeps subdomain scope
[GHSA] GHSA-f7vp-7xgx-4w4r (medium) — Guzzle: Noncanonical cookie domain keeps subdomain scope
GHSA-f7vp-7xgx-4w4r Severity: medium CVE: CVE-2026-69245
Guzzle: Noncanonical cookie domain keeps subdomain scope
### Impact
`SetCookie::matchesDomain()` gives every subdomain of a cookie `Domain` that cookie unless it recognizes the `Domain` as an IP literal or a numeric host, and it decides that from the domain's own text, so two spellings a transport reads as an address keep subdomain scope.
Indicators of compromise
- CVE-2026-69245cve
- CVE-2026-59883cve
Original source: https://github.com/advisories/GHSA-f7vp-7xgx-4w4r