{"id":"UBUNTU-CVE-2026-59883","details":"Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.","modified":"2026-07-15T19:46:49.072765364Z","published":"2026-07-08T17:17:00Z","upstream":["CVE-2026-59883"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-59883"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-59883"},{"type":"REPORT","url":"https://github.com/guzzle/guzzle/security/advisories/GHSA-g446-98w2-8p5w"},{"type":"REPORT","url":"https://github.com/guzzle/guzzle/pull/3694"}],"affected":[{"package":{"name":"guzzle","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/guzzle?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.4.5-1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-guzzlehttp-guzzle","binary_version":"7.4.5-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59883.json"}},{"package":{"name":"guzzle","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/guzzle?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.9.2-0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-guzzlehttp-guzzle","binary_version":"7.9.2-0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59883.json"}},{"package":{"name":"guzzle","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/guzzle?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.9.2-0.1","7.9.2-0.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-guzzlehttp-guzzle","binary_version":"7.9.2-0.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59883.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}