Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PHP Addresses Security Flaw Exposing Sensitive Data

PHP Addresses Security Flaw Exposing Sensitive Data

Posted on September 28, 2026 By CWS

PHP has recently resolved a notable security issue that posed the risk of exposing login credentials and other sensitive information during HTTP redirects. This flaw, identified as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, involved PHP’s HTTP stream wrapper and had been classified as moderately severe.

Understanding the Vulnerability

The vulnerability was triggered when PHP applications utilized the http:// or https:// stream wrapper to access remote content and automatically adhered to redirects. Under these circumstances, PHP inadvertently forwarded sensitive user-supplied request headers to a redirected target without ensuring the destination remained a trusted origin.

Such behavior risked exposing critical headers including Authorization, Cookie, and Proxy-Authorization. These headers often contain vital information such as usernames, passwords, bearer tokens, session cookies, API keys, or proxy credentials.

Implications and Examples

In practical terms, if a PHP application made an authenticated request with an Authorization header and the remote server responded with a redirect to an attacker-controlled domain, older versions of PHP might have sent the authentication header to this malicious endpoint. This risk extended to redirects involving different ports or those downgrading requests from HTTPS to HTTP.

This flaw was particularly concerning for applications that access external resources using PHP stream functions like file_get_contents(), fopen(), or other custom HTTP stream contexts. For a successful exploit, an attacker needed some level of influence over the redirect path, potentially through controlling a URL or operating a third-party service issuing redirects.

Security Measures and Recommendations

PHP’s advisory labeled this issue as a cross-origin credential leak, highlighting that credentials intended for one server should not be automatically sent to another server following a redirect command. This bug parallels a prior credential-forwarding issue that was addressed in libcurl.

To mitigate this risk, PHP maintainers have modified the HTTP stream wrapper to prevent the transmission of sensitive headers across unsafe redirects. Organizations are strongly advised to upgrade PHP to a version containing this critical fix, as confirmed in PHP’s official changelog for PHP 8.

Security teams should also review any applications making authenticated HTTP requests. Developers are encouraged to avoid sending reusable credentials to untrusted URLs, validate redirect targets, limit outbound connections, and prevent HTTPS-to-HTTP downgrades.

While the flaw requires specific redirect conditions, its potential impact is significant. The leakage of bearer tokens or session cookies could allow unauthorized access to internal APIs, cloud services, or application accounts, using credentials that should have remained confined to the original server.

Cyber Security News Tags:Authorization, Credentials, CVE-2026-91766, data leak, HTTP redirect, PHP, Proxy, Security, Update, Vulnerability

Post navigation

Previous Post: Jury Rules Facebook Misled Users on Privacy in New Mexico
Next Post: Critical Citrix NetScaler Flaws Exploited Globally, Warns CISA

Related Posts

Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems Cyber Attack Uses Fake Microsoft Teams Alerts to Breach Systems Cyber Security News
7 Best Security Awareness Training Platforms For MSPs in 2026 7 Best Security Awareness Training Platforms For MSPs in 2026 Cyber Security News
Cloudflare Outage Traced to Emergency React2Shell Patch Deployment Cloudflare Outage Traced to Emergency React2Shell Patch Deployment Cyber Security News
AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods Cyber Security News
AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones Cyber Security News
Record DDoS Intensity in Europe Despite Fewer Attacks Record DDoS Intensity in Europe Despite Fewer Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Citrix NetScaler Vulnerabilities Exploitation
  • DC Health Data Breach Affects Nearly 400,000 Records
  • Critical Citrix NetScaler Flaws Exploited Globally, Warns CISA
  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Citrix NetScaler Vulnerabilities Exploitation
  • DC Health Data Breach Affects Nearly 400,000 Records
  • Critical Citrix NetScaler Flaws Exploited Globally, Warns CISA
  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark