CVE-2026-55767: Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
Impact
CookieJar incorrectly accepts cookies with a dot-only Domain attribute, such as Domain=., Domain=.., Domain=..., and whitespace-padded variants such as Domain= . . In affected versions, SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host.
An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. Applications are affected when they use Guzzle's cookie support, for example new Client(['cookies' => true]) or an explicit shared CookieJar, and reuse the same jar across attacker-controlled and trusted origins.
Applications that do not use Guzzle's cookie support, or that use separate cookie jars per origin or trust boundary, are not affected. This issue is distinct from public suffix list validation: dot-only domains contain no domain label and should not match unrelated hosts.
Patches
The issue is patched in 7.12.1 and later. Starting in that release, Guzzle rejects dot-only cookie Domain attributes and prevents an empty normalized cookie domain from matching any request host.
Workarounds
If you cannot upgrade immediately, do not reuse the same CookieJar instance across untrusted and trusted origins. Use separate cookie jars per origin or trust boundary, or disable cookie handling for requests to untrusted hosts.
Avoid using new Client(['cookies' => true]) for clients that may contact unrelated hosts with different trust levels, because that option creates one shared jar for the client.
Other sources
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/guzzlehttp/guzzleto a version that resolves this vulnerability.Fixed in 7.12.1 - Upgrade
Upgrade
guzzlehttp/guzzleto a version that resolves this vulnerability.Fixed in 7.12.1 - Configuration
Do not use `new Client(['cookies' => true])` for clients that may contact unrelated hosts with different trust levels, because that option creates one shared cookie jar for the client.
Guzzle HTTP client (Cookie handling) Client option cookies = false - Configuration
If you cannot upgrade immediately, do not reuse the same `CookieJar` instance across attacker-controlled/untrusted and trusted origins; use separate cookie jars per origin (or per trust boundary).
Guzzle CookieJar usage CookieJar instance sharing = separate per origin/trust boundary - Configuration
If you cannot upgrade immediately, disable cookie handling for requests to untrusted hosts (so Guzzle does not send cookies derived from untrusted origins to unrelated hosts).
Guzzle Cookie handling for untrusted hosts Cookie handling = disabled for untrusted hosts
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55767?
The severity of CVE-2026-55767 is rated as medium with a score of 5.8.
What impact does CVE-2026-55767 have on applications?
CVE-2026-55767 allows the `CookieJar` to incorrectly accept cookies with a dot-only `Domain` attribute, potentially leading to incorrect domain matching.
How do I fix CVE-2026-55767?
To fix CVE-2026-55767, upgrade to a patched version of the composer/guzzlehttp/guzzle library that addresses this vulnerability.
Which software is affected by CVE-2026-55767?
CVE-2026-55767 affects the composer/guzzlehttp/guzzle library.
When was CVE-2026-55767 published?
CVE-2026-55767 was published on June 19, 2026.