CVE-2026-67339: guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
guzzlehttp/guzzleto a version that resolves this vulnerability.Fixed in 7.14.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure