Guzzle 8.2.0 appears to be a healthy, mature dependency with a long release history, frequent recent releases, a stable non-prerelease version, an active non-archived organization-owned repository, strong documentation and licensing, and a well-structured source tree. Maintenance activity is substantial, with 326 commits and 11 merged pull requests recently, while repository workflows use read-only permissions and show no analyzed dangerous patterns. The main concern is concentrated recent contribution activity: one maintainer made about 99.1% of the last three months' commits, and the repository reports no security-scanning tools; however, three active maintainers, organization backing, a security policy, and extensive project maturity partly mitigate these risks. The package is suitable for dependency use, subject to normal review of updates.
88%
Total Score
90
100
94
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-69246 guzzlehttp/guzzle is vulnerable to Incorrect Behavior Order: Validate Before Canonicalize in versions 0.0.0 - 7.15.2 and 8.0.0 - 8.0.1. | 0.0.0 - 7.15.28.0.0 - 8.0.1 | High |
CVE-2026-69245 guzzlehttp/guzzle is vulnerable to Incorrect Behavior Order: Validate Before Canonicalize in versions 0.0.0 - 7.15.2 and 8.0.0 - 8.0.1. | 0.0.0 - 7.15.28.0.0 - 8.0.1 | Medium |
AIKIDO-2026-74412 guzzlehttp/guzzle is vulnerable to Origin Validation Error in versions 0.0.1 - 7.15.1 and 8.0.0 - 8.0.0. | 0.0.1 - 7.15.18.0.0 - 8.0.0 | Medium |
AIKIDO-2026-75039 guzzlehttp/guzzle is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 7.15.1 and 8.0.0 - 8.0.0. | 0.0.1 - 7.15.18.0.0 - 8.0.0 | High |
CVE-2026-59883 guzzlehttp/guzzle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 7.12.3. | 0.0.0 - 7.12.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^3.1 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
guzzlehttp/promises Version ^3.0.2 | — | — |
symfony/polyfill-php80 Version ^1.25 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.