
CVE-2026-69245 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::… https://www.cve.org/CVERecord?id=CVE-2026-69245
Post summary
The note details a cookie domain handling flaw in Guzzle's SetCookie::matchesDomain() that is fixed in versions 7.15.2 and 8.0.1, highlighting the need to upgrade for remediation.

