Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ViewSonic vCast Vulnerabilities Let Attackers Seize Control
September 28, 2026
Critical Kiteworks Zero-Day Vulnerability Prompts Server Shutdown Warning
September 28, 2026
CISA Warns of Critical Citrix NetScaler RCE 0-Day Vulnerabilities Under Attack
September 28, 2026
Home/Vulnerabilities/PHP Patches Critical Credential Exposure Vulnerability
Vulnerabilities

PHP Patches Critical Credential Exposure Vulnerability

Key Takeaways A critical vulnerability in PHP’s HTTP stream wrapper, CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), could lead to the exposure of sensitive user credentials during HTTP redirects. The...

Marcus Rodriguez
Marcus Rodriguez
September 28, 2026 4 Min Read
3 0

Key Takeaways

  • A critical vulnerability in PHP’s HTTP stream wrapper, CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), could lead to the exposure of sensitive user credentials during HTTP redirects.
  • The flaw specifically affects PHP applications that utilize the http:// or https:// stream wrapper and automatically follow redirects.
  • Authorization, Cookie, and Proxy-Authorization headers, potentially containing usernames, passwords, API keys, or session tokens, are at risk of being inadvertently transmitted to untrusted destinations.
  • PHP has released patches for supported versions, and immediate upgrades are strongly advised for all affected systems.

PHP Patches Critical Credential Exposure Vulnerability

PHP developers have addressed a significant security flaw that could inadvertently expose sensitive login credentials, session cookies, and proxy authentication data to unauthorized servers during HTTP redirect operations. This vulnerability, identified as CVE-2026-91766 and tracked internally as GHSA-fpwc-w8rq-cr92, impacts PHP’s HTTP stream wrapper, though it has been assigned a moderate severity rating.

Table Of Content

  • Key Takeaways
  • PHP Patches Critical Credential Exposure Vulnerability
  • Understanding the Vulnerability
  • Patch Availability and Recommendation
  • What You Should Do

Understanding the Vulnerability

The core of the issue arises when a PHP application leverages the http:// or https:// stream wrapper to fetch remote content and is configured to automatically follow redirects. Under specific conditions, PHP would transmit user-supplied sensitive request headers to the redirect’s destination without adequately verifying that the new location belonged to the original, trusted origin. This behavior is particularly problematic as it can lead to the leakage of critical headers such as Authorization, Cookie, and Proxy-Authorization. These headers frequently contain highly sensitive information, including usernames, passwords, bearer tokens, session cookies, API keys, or proxy credentials, all of which could be exploited by malicious actors.

For instance, consider a scenario where an application makes an authenticated request to https://api.example.com/data, including an Authorization header. If the remote server then issues a redirect to a different host controlled by an attacker, older, unpatched PHP versions could unknowingly forward that same authentication header to the attacker’s domain. The risk extends beyond redirects to entirely different hosts; it also encompasses redirects to alternate ports or those that downgrade a secure HTTPS connection to an unencrypted HTTP request, further increasing the potential for data interception.

This flaw is particularly pertinent for applications that retrieve external resources using PHP stream functions like file_get_contents(), fopen(), readfile(), or any custom code built around HTTP stream contexts. For an exploit to occur, a vulnerable application must both supply sensitive headers and follow a redirect that is either controlled or influenced by an attacker. It’s important to note that an attacker doesn’t necessarily need to compromise the original trusted server. They might exploit this vulnerability by controlling a URL requested by the PHP application, operating a third-party service capable of issuing redirects, or manipulating a redirect path through another application weakness.

PHP’s advisory describes the issue as a “cross-origin credential leak.” The term “cross-origin” signifies that the redirected request traverses beyond the initial combination of scheme, host, and port. The fundamental principle violated here is that credentials intended for one specific server should never be automatically transmitted to another server solely because a redirect response dictated it.

This bug shares similarities with a previously identified credential-forwarding weakness that was addressed in libcurl. PHP maintainers have now updated the HTTP stream wrapper’s behavior to prevent sensitive headers from being carried across unsafe redirect boundaries, thereby mitigating this risk.

Patch Availability and Recommendation

Organizations are strongly urged to upgrade their PHP installations to a patched release as quickly as possible. PHP’s official PHP 8 changelog confirms that supported release branches have received a fix for GHSA-fpwc-w8rq-cr92, corresponding to CVE-2026-91766. While the flaw necessitates a redirect-related condition, its potential impact is substantial. A leaked bearer token or session cookie could grant an attacker unauthorized access to internal APIs, cloud services, application accounts, or proxy infrastructure, all utilizing credentials that were never meant to leave their original secure context.

What You Should Do

  • Upgrade PHP Immediately: Ensure all PHP installations are updated to the latest patched versions that contain the fix for CVE-2026-91766 (GHSA-fpwc-w8rq-cr92).
  • Review Application Code: Conduct a thorough review of applications that make authenticated outbound HTTP requests, especially those using PHP stream functions like file_get_contents(), fopen(), or readfile().
  • Validate Redirect Destinations: Implement robust validation mechanisms for redirect destinations, ensuring that sensitive headers are only sent to trusted, expected origins.
  • Avoid Reusable Credentials on Untrusted URLs: Refrain from attaching reusable credentials to requests directed at untrusted or potentially malicious URLs.
  • Restrict Outbound Connections: Where feasible, limit outbound HTTP connections from your PHP applications to only necessary and trusted endpoints.
  • Prevent HTTPS-to-HTTP Downgrades: Configure applications and infrastructure to prevent any redirects that downgrade a secure HTTPS connection to an unencrypted HTTP connection.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Cloud Credential Theft: Attackers Exploit Stolen Keys for Cloud Access

Next Post

CISA Warns of Critical Citrix NetScaler RCE 0-Day Vulnerabilities Under Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Python MaaS Infostealer Steals Passwords, Credit Cards, and Cookies
September 28, 2026
Top Adaptive & Risk-Based Authentication Tools for 2026
September 28, 2026
Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
September 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us