PHP has recently resolved a notable security issue that posed the risk of exposing login credentials and other sensitive information during HTTP redirects. This flaw, identified as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, involved PHP’s HTTP stream wrapper and had been classified as moderately severe.
Understanding the Vulnerability
The vulnerability was triggered when PHP applications utilized the http:// or https:// stream wrapper to access remote content and automatically adhered to redirects. Under these circumstances, PHP inadvertently forwarded sensitive user-supplied request headers to a redirected target without ensuring the destination remained a trusted origin.
Such behavior risked exposing critical headers including Authorization, Cookie, and Proxy-Authorization. These headers often contain vital information such as usernames, passwords, bearer tokens, session cookies, API keys, or proxy credentials.
Implications and Examples
In practical terms, if a PHP application made an authenticated request with an Authorization header and the remote server responded with a redirect to an attacker-controlled domain, older versions of PHP might have sent the authentication header to this malicious endpoint. This risk extended to redirects involving different ports or those downgrading requests from HTTPS to HTTP.
This flaw was particularly concerning for applications that access external resources using PHP stream functions like file_get_contents(), fopen(), or other custom HTTP stream contexts. For a successful exploit, an attacker needed some level of influence over the redirect path, potentially through controlling a URL or operating a third-party service issuing redirects.
Security Measures and Recommendations
PHP’s advisory labeled this issue as a cross-origin credential leak, highlighting that credentials intended for one server should not be automatically sent to another server following a redirect command. This bug parallels a prior credential-forwarding issue that was addressed in libcurl.
To mitigate this risk, PHP maintainers have modified the HTTP stream wrapper to prevent the transmission of sensitive headers across unsafe redirects. Organizations are strongly advised to upgrade PHP to a version containing this critical fix, as confirmed in PHP’s official changelog for PHP 8.
Security teams should also review any applications making authenticated HTTP requests. Developers are encouraged to avoid sending reusable credentials to untrusted URLs, validate redirect targets, limit outbound connections, and prevent HTTPS-to-HTTP downgrades.
While the flaw requires specific redirect conditions, its potential impact is significant. The leakage of bearer tokens or session cookies could allow unauthorized access to internal APIs, cloud services, or application accounts, using credentials that should have remained confined to the original server.
