CVE-2026-55824
Description
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
contao/contaoPackagist | >= 4.13.0, < 5.3.47 | 5.3.47 |
contao/contaoPackagist | >= 5.4.0, < 5.7.7 | 5.7.7 |
contao/core-bundlePackagist | >= 4.13.0, < 5.3.47 | 5.3.47 |
contao/core-bundlePackagist | >= 5.4.0, < 5.7.7 | 5.7.7 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-3mr9-p497-58f6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55824ghsaADVISORY
- contao.org/en/security-advisories/credentials-disclosure-in-the-crawlerghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2026-55824.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2026-55824.yamlghsaWEB
- github.com/contao/contao/commit/5bc6e3f900c439313df57aa561d0865792aafa05ghsaWEB
- github.com/contao/contao/commit/80425d28cdf66280a209bd3f5bc31b1a76901a04ghsaWEB
- github.com/contao/contao/security/advisories/GHSA-3mr9-p497-58f6nvdWEB
News mentions
0No linked articles in our index yet.