Severity
High
Analysis Summary
PHP has fixed a moderate-severity security vulnerability, tracked as CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), in its HTTP stream wrapper that could cause sensitive authentication data to be disclosed during HTTP redirects. The flaw affects applications using PHP’s http:// or https:// stream wrappers to retrieve remote resources while automatically following redirects. Under vulnerable conditions, PHP could forward user-supplied Authorization, Cookie, and Proxy-Authorization headers to a redirected destination without verifying that the destination remained within the same trusted origin.
The vulnerability could expose sensitive credentials, including usernames and passwords, bearer tokens, session cookies, API keys, and proxy authentication data. For example, an application could send an authenticated request to https://api.example.com/data, but if the server redirected the request to an attacker-controlled domain, vulnerable PHP versions could forward the original authentication headers to that domain. The risk also applies when redirects move to a different host, port, or scheme, including HTTPS-to-HTTP downgrades. The issue is particularly relevant to applications using functions such as file_get_contents(), fopen(), readfile(), or custom HTTP stream-context implementations that include sensitive headers.
Exploitation requires specific conditions: the PHP application must make an authenticated outbound HTTP request, automatically follow redirects, and use a redirect that is controlled by or influenced by an attacker. An attacker could potentially exploit this through a URL controlled by them, a third-party service capable of issuing redirects, or another application weakness that allows redirect manipulation. PHP describes the vulnerability as a cross-origin credential leak, where credentials intended for one combination of scheme, host, and port may be unintentionally sent to another origin. If stolen credentials remain valid, attackers could potentially use leaked bearer tokens, session cookies, API keys, or proxy credentials to access protected APIs, application accounts, cloud services, or proxy infrastructure.
PHP maintainers have addressed the issue by changing HTTP stream wrapper behavior so that sensitive headers are not carried across unsafe redirect boundaries. Supported PHP 8 release branches include fixes for CVE-2026-91766/GHSA-fpwc-w8rq-cr92. Organizations should upgrade affected PHP installations to a patched version and review applications that perform authenticated outbound HTTP requests. Developers should avoid sending reusable credentials to untrusted URLs, validate redirect destinations, restrict outbound connections where practical, and prevent HTTPS-to-HTTP downgrade redirects. Security teams should also assess logs and outbound HTTP activity for unexpected redirects involving authenticated requests, as exploitation could result in credential disclosure even without direct compromise of the original trusted server.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2026-91766
Remediation
- Upgrade PHP to the latest supported version containing the fix for CVE-2026-91766.
- Review applications using file_get_contents(), fopen(), readfile(), or HTTP stream wrappers for authenticated outbound requests.
- Validate redirect destinations before forwarding requests containing Authorization, Cookie, or Proxy-Authorization headers.
- Prevent sensitive credentials from being forwarded across different hosts, ports, or schemes.
- Block HTTPS-to-HTTP redirect downgrades for authenticated requests.
- Avoid attaching reusable credentials to requests targeting untrusted or user-controlled URLs.
- Restrict outbound connections to approved and trusted destinations where possible.
- Review HTTP and application logs for unexpected redirects involving authenticated requests.
- Rotate potentially exposed API keys, session tokens, bearer tokens, and proxy credentials if suspicious activity is identified.
- Monitor for unauthorized use of credentials that may have been exposed through malicious redirects.

