PHP Patches Critical Credential Exposure Vulnerability
Key Takeaways A critical vulnerability in PHP’s HTTP stream wrapper, CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), could lead to the exposure of sensitive user credentials during HTTP redirects. The...
Key Takeaways
- A critical vulnerability in PHP’s HTTP stream wrapper, CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), could lead to the exposure of sensitive user credentials during HTTP redirects.
- The flaw specifically affects PHP applications that utilize the
http://orhttps://stream wrapper and automatically follow redirects. - Authorization, Cookie, and Proxy-Authorization headers, potentially containing usernames, passwords, API keys, or session tokens, are at risk of being inadvertently transmitted to untrusted destinations.
- PHP has released patches for supported versions, and immediate upgrades are strongly advised for all affected systems.
PHP Patches Critical Credential Exposure Vulnerability
PHP developers have addressed a significant security flaw that could inadvertently expose sensitive login credentials, session cookies, and proxy authentication data to unauthorized servers during HTTP redirect operations. This vulnerability, identified as CVE-2026-91766 and tracked internally as GHSA-fpwc-w8rq-cr92, impacts PHP’s HTTP stream wrapper, though it has been assigned a moderate severity rating.
Table Of Content
Understanding the Vulnerability
The core of the issue arises when a PHP application leverages the http:// or https:// stream wrapper to fetch remote content and is configured to automatically follow redirects. Under specific conditions, PHP would transmit user-supplied sensitive request headers to the redirect’s destination without adequately verifying that the new location belonged to the original, trusted origin. This behavior is particularly problematic as it can lead to the leakage of critical headers such as Authorization, Cookie, and Proxy-Authorization. These headers frequently contain highly sensitive information, including usernames, passwords, bearer tokens, session cookies, API keys, or proxy credentials, all of which could be exploited by malicious actors.
For instance, consider a scenario where an application makes an authenticated request to https://api.example.com/data, including an Authorization header. If the remote server then issues a redirect to a different host controlled by an attacker, older, unpatched PHP versions could unknowingly forward that same authentication header to the attacker’s domain. The risk extends beyond redirects to entirely different hosts; it also encompasses redirects to alternate ports or those that downgrade a secure HTTPS connection to an unencrypted HTTP request, further increasing the potential for data interception.
This flaw is particularly pertinent for applications that retrieve external resources using PHP stream functions like file_get_contents(), fopen(), readfile(), or any custom code built around HTTP stream contexts. For an exploit to occur, a vulnerable application must both supply sensitive headers and follow a redirect that is either controlled or influenced by an attacker. It’s important to note that an attacker doesn’t necessarily need to compromise the original trusted server. They might exploit this vulnerability by controlling a URL requested by the PHP application, operating a third-party service capable of issuing redirects, or manipulating a redirect path through another application weakness.
PHP’s advisory describes the issue as a “cross-origin credential leak.” The term “cross-origin” signifies that the redirected request traverses beyond the initial combination of scheme, host, and port. The fundamental principle violated here is that credentials intended for one specific server should never be automatically transmitted to another server solely because a redirect response dictated it.
This bug shares similarities with a previously identified credential-forwarding weakness that was addressed in libcurl. PHP maintainers have now updated the HTTP stream wrapper’s behavior to prevent sensitive headers from being carried across unsafe redirect boundaries, thereby mitigating this risk.
Patch Availability and Recommendation
Organizations are strongly urged to upgrade their PHP installations to a patched release as quickly as possible. PHP’s official PHP 8 changelog confirms that supported release branches have received a fix for GHSA-fpwc-w8rq-cr92, corresponding to CVE-2026-91766. While the flaw necessitates a redirect-related condition, its potential impact is substantial. A leaked bearer token or session cookie could grant an attacker unauthorized access to internal APIs, cloud services, application accounts, or proxy infrastructure, all utilizing credentials that were never meant to leave their original secure context.
What You Should Do
- Upgrade PHP Immediately: Ensure all PHP installations are updated to the latest patched versions that contain the fix for CVE-2026-91766 (GHSA-fpwc-w8rq-cr92).
- Review Application Code: Conduct a thorough review of applications that make authenticated outbound HTTP requests, especially those using PHP stream functions like
file_get_contents(),fopen(), orreadfile(). - Validate Redirect Destinations: Implement robust validation mechanisms for redirect destinations, ensuring that sensitive headers are only sent to trusted, expected origins.
- Avoid Reusable Credentials on Untrusted URLs: Refrain from attaching reusable credentials to requests directed at untrusted or potentially malicious URLs.
- Restrict Outbound Connections: Where feasible, limit outbound HTTP connections from your PHP applications to only necessary and trusted endpoints.
- Prevent HTTPS-to-HTTP Downgrades: Configure applications and infrastructure to prevent any redirects that downgrade a secure HTTPS connection to an unencrypted HTTP connection.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.