PHP Credential Leak

Overview

PHP has patched a security vulnerability that could cause sensitive credentials to be forwarded to an unintended server when an application follows an HTTP redirect. Tracked as CVE-2026-91766, the flaw affects PHP’s HTTP stream wrapper and could expose authentication headers, cookies, bearer tokens, API credentials and proxy authentication information. The vulnerability is rated moderate, but its significance is broader than the severity score suggests. It demonstrates how credentials intended for one trusted service can cross a security boundary simply because an application follows a redirect.

How the Vulnerability Worked

PHP applications can retrieve remote resources using functions such as file_get_contents() and fopen() through the HTTP and HTTPS stream wrappers. Applications may also attach sensitive headers such as:

  • Authorization
  • Cookie
  • Proxy-Authorization

Under vulnerable conditions, if the destination server responded with a redirect, PHP could forward those headers to the new destination without confirming that it remained within the original trusted origin. That destination could be a different hostname, another port or even a downgrade from encrypted HTTPS to unencrypted HTTP. A credential intended for one API could therefore be delivered to a completely different server.

The Problem Is Trust, Not Simply Redirects

Redirects are a normal part of web architecture and are used extensively across APIs, authentication systems and cloud services. The security problem appears when trust assigned to the original destination automatically follows the redirect. An application may legitimately trust api.company.com with a bearer token, but that does not mean the same credential should automatically be trusted by wherever that server redirects the request. This becomes particularly important in environments where applications communicate with multiple SaaS platforms, internal APIs and external services using reusable service credentials.

Why Credential Leakage Matters

A leaked header can provide far more than temporary application access. Bearer tokens and session cookies may provide access to APIs or cloud services, while proxy credentials could expose supporting network infrastructure. The vulnerability therefore demonstrates how a relatively small weakness in an HTTP client can potentially cross several layers of an enterprise architecture. No server compromise is necessarily required if an attacker can influence the URL being requested or control part of the redirect chain.

Strengthening Outbound Application Security

PHP has changed the affected behaviour in supported releases, preventing sensitive headers from automatically crossing unsafe redirect boundaries. Affected environments should move to fixed PHP releases while application architectures should also review authenticated outbound requests. Sensitive credentials should be scoped to specific destinations wherever possible, redirect destinations should be validated, HTTPS downgrade paths should be avoided and outbound connectivity should be restricted according to application requirements. These controls reduce the impact of both software vulnerabilities and application-level redirect manipulation.

Expert in the Cloud Insight

CVE-2026-91766 illustrates an important principle in modern application security:

trust should not automatically travel with the connection.

Authentication credentials are issued within a particular security context. When the hostname, protocol or destination changes, that trust relationship should be evaluated again. The same principle applies across APIs, cloud services, identity platforms and service-to-service communication. A redirect may appear to be a simple networking function, but when credentials are attached, it becomes a trust-boundary decision. Credentials should follow verified identity—not simply follow the URL.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.