VYPR
Low severity2.6NVD Advisory· Published Jul 31, 2026· Updated Sep 8, 2026

CVE-2026-55824

CVE-2026-55824

Description

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
contao/contaoPackagist
>= 4.13.0, < 5.3.475.3.47
contao/contaoPackagist
>= 5.4.0, < 5.7.75.7.7
contao/core-bundlePackagist
>= 4.13.0, < 5.3.475.3.47
contao/core-bundlePackagist
>= 5.4.0, < 5.7.75.7.7

Affected products

1
  • Contao/CMSllm-create
    Range: 4.13.40 - 5.3.46, 5.7.0-RC1 - 5.7.6

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.