Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PHP Addresses Security Flaw Exposing Sensitive Data

PHP Addresses Security Flaw Exposing Sensitive Data

Posted on September 28, 2026 By CWS

PHP has recently resolved a notable security issue that posed the risk of exposing login credentials and other sensitive information during HTTP redirects. This flaw, identified as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, involved PHP’s HTTP stream wrapper and had been classified as moderately severe.

Understanding the Vulnerability

The vulnerability was triggered when PHP applications utilized the http:// or https:// stream wrapper to access remote content and automatically adhered to redirects. Under these circumstances, PHP inadvertently forwarded sensitive user-supplied request headers to a redirected target without ensuring the destination remained a trusted origin.

Such behavior risked exposing critical headers including Authorization, Cookie, and Proxy-Authorization. These headers often contain vital information such as usernames, passwords, bearer tokens, session cookies, API keys, or proxy credentials.

Implications and Examples

In practical terms, if a PHP application made an authenticated request with an Authorization header and the remote server responded with a redirect to an attacker-controlled domain, older versions of PHP might have sent the authentication header to this malicious endpoint. This risk extended to redirects involving different ports or those downgrading requests from HTTPS to HTTP.

This flaw was particularly concerning for applications that access external resources using PHP stream functions like file_get_contents(), fopen(), or other custom HTTP stream contexts. For a successful exploit, an attacker needed some level of influence over the redirect path, potentially through controlling a URL or operating a third-party service issuing redirects.

Security Measures and Recommendations

PHP’s advisory labeled this issue as a cross-origin credential leak, highlighting that credentials intended for one server should not be automatically sent to another server following a redirect command. This bug parallels a prior credential-forwarding issue that was addressed in libcurl.

To mitigate this risk, PHP maintainers have modified the HTTP stream wrapper to prevent the transmission of sensitive headers across unsafe redirects. Organizations are strongly advised to upgrade PHP to a version containing this critical fix, as confirmed in PHP’s official changelog for PHP 8.

Security teams should also review any applications making authenticated HTTP requests. Developers are encouraged to avoid sending reusable credentials to untrusted URLs, validate redirect targets, limit outbound connections, and prevent HTTPS-to-HTTP downgrades.

While the flaw requires specific redirect conditions, its potential impact is significant. The leakage of bearer tokens or session cookies could allow unauthorized access to internal APIs, cloud services, or application accounts, using credentials that should have remained confined to the original server.

Cyber Security News Tags:Authorization, Credentials, CVE-2026-91766, data leak, HTTP redirect, PHP, Proxy, Security, Update, Vulnerability

Post navigation

Previous Post: Jury Rules Facebook Misled Users on Privacy in New Mexico

Related Posts

Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Cyber Security News
Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers Cyber Security News
Microsoft Details ASP.NET Vulnerability That Enables Attackers To Smuggle HTTP Requests Microsoft Details ASP.NET Vulnerability That Enables Attackers To Smuggle HTTP Requests Cyber Security News
New Supply Chain Attack Hits npm, PyPI, and Crates New Supply Chain Attack Hits npm, PyPI, and Crates Cyber Security News
Dark Caracal Hackers Leverage Ethereum for Malware Resilience Dark Caracal Hackers Leverage Ethereum for Malware Resilience Cyber Security News
Hackers can Hijack Your Dash Cams in Seconds and Weaponize it for Future Attacks Hackers can Hijack Your Dash Cams in Seconds and Weaponize it for Future Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico
  • JADEPUFFER Exploits Azure to Delete Resources
  • Kiteworks Addresses Security Threat with Server Shutdown
  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico
  • JADEPUFFER Exploits Azure to Delete Resources
  • Kiteworks Addresses Security Threat with Server Shutdown
  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark