VYPR
patchPublished Sep 28, 2026· 1 source

PHP Fixes HTTP Redirect Flaw Exposing Credentials

PHP has patched a critical vulnerability in its HTTP stream wrapper that could leak sensitive credentials, cookies, and authentication data to unintended servers during redirects.

PHP has addressed a significant security flaw within its HTTP stream wrapper that posed a risk of exposing sensitive user data, including login credentials, session cookies, and proxy authentication details, to unauthorized servers during HTTP redirects. The vulnerability, identified as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, has been classified with moderate severity by PHP maintainers.

The core of the issue lies in how PHP's http:// and https:// stream wrappers handle redirects. When a PHP application requests remote content and receives a redirect response, older versions of PHP would automatically forward sensitive request headers, such as Authorization, Cookie, and Proxy-Authorization, to the new destination. Crucially, this forwarding occurred without verifying if the redirect led to a trusted origin, potentially sending credentials intended for a legitimate server to an attacker-controlled server.

This cross-origin credential leak could have severe implications. For instance, an authenticated request to a legitimate API endpoint containing an Authorization header with a bearer token or API key could be redirected by an attacker to their own server. The attacker would then receive these sensitive credentials, granting them access to internal APIs, cloud services, or application accounts that the original credentials were meant to protect. The vulnerability also extended to redirects that downgraded a secure HTTPS connection to an unencrypted HTTP connection, further increasing the risk of data interception.

The vulnerability is particularly relevant for applications that utilize PHP's built-in stream functions like file_get_contents(), fopen(), or readfile() to fetch external resources. Exploitation requires a scenario where a vulnerable application supplies sensitive headers and subsequently follows a redirect that is either controlled by or influenced by an attacker. This could be achieved by an attacker controlling a URL the application accesses, operating a service that issues malicious redirects, or exploiting a separate weakness to manipulate redirect paths.

PHP developers have rectified this by modifying the HTTP stream wrapper's behavior. The updated code now prevents sensitive headers from being automatically forwarded across redirect boundaries that are deemed unsafe or cross-origin. This change aligns with similar fixes implemented in libraries like libcurl to address analogous credential-forwarding weaknesses.

Organizations are strongly advised to update their PHP installations to the latest versions that incorporate this fix. Beyond patching, security teams should review applications that make authenticated outbound HTTP requests. Best practices include validating redirect destinations, restricting outbound connections where feasible, and implementing measures to prevent HTTPS-to-HTTP downgrade attacks. Developers should also exercise caution when attaching reusable credentials to requests targeting untrusted URLs.

The impact of this vulnerability, while dependent on specific application configurations and the presence of redirects, can be substantial. A leaked session cookie or bearer token could provide attackers with a direct pathway to compromise user accounts or sensitive backend systems, bypassing the intended security controls. The fix aims to close this potential avenue for credential theft and unauthorized access.

Synthesized by Vypr AI