Insecure Redirection in PHP HTTP Stream Wrapper Affects Users' Credentials
CVE-2026-91766
5.9MEDIUM
What is CVE-2026-91766?
The PHP HTTP stream wrapper presents a vulnerability that allows user-supplied Authorization, Cookie, and Proxy-Authorization headers to be forwarded unchanged during redirects to different hosts or ports, including downgrades from HTTPS to HTTP. This flaw enables scenarios where credentials intended for secure connections may be exposed to malicious servers that can manipulate redirects. Mitigation is essential to prevent potential security breaches associated with sensitive user information.
Affected Version(s)
PHP 8.2.* < 8.2.34
PHP 8.3.* < 8.3.35
PHP 8.4.* < 8.4.26
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
@q2a3z (GitHub)
Ilia Alshanetsky
Alexandre Daubois
Tim DĂĽsterhus
Arnaud Le Blanc
Jakub Zelenka
