CVE Explorer
CVE-2026-55568
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMulti
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-636","description":"CWE-636: Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-319","description":"CWE-319: Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-311","description":"CWE-311: Missing Encryption of Sensitive Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"guzzle","vendor":"guzzle","versions":[{"status":"affected","version":"< 7.12.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-636","description":"CWE-636: Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-319","description":"CWE-319: Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-311","description":"CWE-311: Missing Encryption of Sensitive Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b58c0d3dece42f41042a25644c2f3bf5ab1d36023083b3952e18588e89d9a167 · sha256:bcafe80799178676… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.