>= 6, < 6.2.1
from 0, < 6.5.6
HIGH7.7CVE-2022-31091Change in port should be considered a change in origin from 0, < 6.5.8
HIGH7.7CVE-2022-31090CURLOPT_HTTPAUTH option not cleared on change of origin from 0, < 6.5.8
HIGH7.5Fix failure to strip Authorization header on HTTP downgrade in Guzzle
>= 4.0.0, < 6.5.7
HIGH7.5Fix failure to strip Authorization header on HTTP downgrade in Guzzle
>= 4.0.0, < 6.5.7
MEDIUM5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
from 0, < 7.12.1
MEDIUM5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
from 0, < 7.12.1
MEDIUM4.7Guzzle: Cookie Disclosure and Injection via IP-Address Domains
from 0, < 7.12.3