Rewterz

WordPress Flaw Enables Malicious Code Execution

September 25, 2026
Rewterz

Apple CoreGraphics Zero-Day Actively Exploited

September 29, 2026

PHP Bug Could Leak Login Credentials

Severity

High

Analysis Summary

PHP has fixed a moderate-severity security vulnerability, tracked as CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), in its HTTP stream wrapper that could cause sensitive authentication data to be disclosed during HTTP redirects. The flaw affects applications using PHP’s http:// or https:// stream wrappers to retrieve remote resources while automatically following redirects. Under vulnerable conditions, PHP could forward user-supplied Authorization, Cookie, and Proxy-Authorization headers to a redirected destination without verifying that the destination remained within the same trusted origin.

The vulnerability could expose sensitive credentials, including usernames and passwords, bearer tokens, session cookies, API keys, and proxy authentication data. For example, an application could send an authenticated request to https://api.example.com/data, but if the server redirected the request to an attacker-controlled domain, vulnerable PHP versions could forward the original authentication headers to that domain. The risk also applies when redirects move to a different host, port, or scheme, including HTTPS-to-HTTP downgrades. The issue is particularly relevant to applications using functions such as file_get_contents(), fopen(), readfile(), or custom HTTP stream-context implementations that include sensitive headers.

Exploitation requires specific conditions: the PHP application must make an authenticated outbound HTTP request, automatically follow redirects, and use a redirect that is controlled by or influenced by an attacker. An attacker could potentially exploit this through a URL controlled by them, a third-party service capable of issuing redirects, or another application weakness that allows redirect manipulation. PHP describes the vulnerability as a cross-origin credential leak, where credentials intended for one combination of scheme, host, and port may be unintentionally sent to another origin. If stolen credentials remain valid, attackers could potentially use leaked bearer tokens, session cookies, API keys, or proxy credentials to access protected APIs, application accounts, cloud services, or proxy infrastructure.

PHP maintainers have addressed the issue by changing HTTP stream wrapper behavior so that sensitive headers are not carried across unsafe redirect boundaries. Supported PHP 8 release branches include fixes for CVE-2026-91766/GHSA-fpwc-w8rq-cr92. Organizations should upgrade affected PHP installations to a patched version and review applications that perform authenticated outbound HTTP requests. Developers should avoid sending reusable credentials to untrusted URLs, validate redirect destinations, restrict outbound connections where practical, and prevent HTTPS-to-HTTP downgrade redirects. Security teams should also assess logs and outbound HTTP activity for unexpected redirects involving authenticated requests, as exploitation could result in credential disclosure even without direct compromise of the original trusted server.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-91766

Remediation

  • Upgrade PHP to the latest supported version containing the fix for CVE-2026-91766.
  • Review applications using file_get_contents(), fopen(), readfile(), or HTTP stream wrappers for authenticated outbound requests.
  • Validate redirect destinations before forwarding requests containing Authorization, Cookie, or Proxy-Authorization headers.
  • Prevent sensitive credentials from being forwarded across different hosts, ports, or schemes.
  • Block HTTPS-to-HTTP redirect downgrades for authenticated requests.
  • Avoid attaching reusable credentials to requests targeting untrusted or user-controlled URLs.
  • Restrict outbound connections to approved and trusted destinations where possible.
  • Review HTTP and application logs for unexpected redirects involving authenticated requests.
  • Rotate potentially exposed API keys, session tokens, bearer tokens, and proxy credentials if suspicious activity is identified.
  • Monitor for unauthorized use of credentials that may have been exposed through malicious redirects.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.