CVE-2026-67339

Description

A flaw was found in guzzlehttp/guzzle, where it fails to properly isolate Proxy-Authorization headers from origin servers when using cURL handlers. A remote attacker could exploit this vulnerability when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections. This improper isolation allows attackers to capture sensitive proxy credentials through origin server access logs, leading to information disclosure.

Statement

No Red Hat products ship guzzlehttp/guzzle. Community builds of nextcloud and roundcubemail in Fedora and EPEL ship patched versions (7.15.2 and 7.15.3 respectively, fix version is 7.14.2).

Mitigation

Upgrade guzzlehttp/guzzle to version 7.14.2 or later.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Files or Directories; Read Memory; Read Application Data

Sensitive data may be exposed to attackers.

Frequently Asked Questions

Want to get errata notifications? Sign up here.