PHP Fixed a Bug That Could Send Your Login Credentials to the Wrong Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


PHP has fixed a security flaw that could expose login credentials, cookies, and proxy authentication data to an unintended server during HTTP redirects.

The vulnerability, tracked as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, affects PHP’s HTTP stream wrapper and has been rated as moderate severity.

The issue occurs when a PHP application uses the http:// or https:// stream wrapper to request remote content and automatically follows a redirect.

Under vulnerable conditions, PHP forwards user-supplied sensitive request headers to the redirect destination without confirming the destination is still the same trusted origin.

This behavior could expose Authorization, Cookie, and Proxy-Authorization headers. These headers may contain usernames and passwords, bearer tokens, session cookies, API keys, or proxy credentials.

For example, an application may make an authenticated request to https://api.example.com/data with an Authorization header.

PHP Fixed a Bug

If the remote server responds with a redirect to another host controlled by an attacker, older PHP versions could send the same authentication header to the attacker-controlled domain. The risk also includes redirects to a different port or redirects that downgrade a request from HTTPS to unencrypted HTTP.

The flaw is especially relevant for applications that retrieve external resources through PHP stream functions such as file_get_contents(), fopen(), readfile(), or custom code built around HTTP stream contexts. A vulnerable application must both supply sensitive headers and follow a redirect controlled by, or influenced by, an attacker.

An attacker does not need to compromise the original trusted server in every scenario. They may be able to exploit the problem if they control a URL requested by the PHP application, operate a third-party service that can issue redirects, or can manipulate a redirect path through a separate application weakness.

PHP’s advisory describes the issue as a cross-origin credential leak. “Cross-origin” means the redirected request moves beyond the original combination of scheme, host, and port.

Credentials intended for one server should not automatically be sent to another server simply because a redirect response instructed the client to do so.

The bug is similar to an older credential-forwarding weakness fixed in libcurl. PHP maintainers have now changed the HTTP stream wrapper behavior to prevent sensitive headers from being carried across unsafe redirect boundaries.

Organizations should upgrade PHP to a release containing the fix as soon as possible. PHP’s official PHP 8 changelog confirms that supported release branches received a fix for GHSA-fpwc-w8rq-cr92, identified as CVE-2026-91766.

Security teams should also review applications that make authenticated outbound HTTP requests. Developers should avoid attaching reusable credentials to requests for untrusted URLs, validate redirect destinations, restrict outbound connections where possible, and prevent HTTPS-to-HTTP downgrade redirects.

Although the flaw requires a redirect-related condition, the impact can be significant. A leaked bearer token or session cookie could allow an attacker to access internal APIs, cloud services, application accounts, or proxy infrastructure using credentials that were never intended to leave the original server.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post PHP Fixed a Bug That Could Send Your Login Credentials to the Wrong Server appeared first on Cyber Security News.