CVE-2026-91766: CWE-200 in PHP Group PHP
CVE-2026-91766 is a medium severity information disclosure vulnerability in PHP's http:// stream wrapper. When following redirects, it forwards user-supplied Authorization, Cookie, and Proxy-Authorization headers unchanged, even if the redirect target is a different host, port, or downgrades from HTTPS to HTTP. This can expose sensitive credentials to unintended servers.
AI Analysis
Technical Summary
The vulnerability occurs in the PHP http:// stream wrapper where it improperly forwards sensitive headers such as Authorization, Cookie, and Proxy-Authorization when following HTTP redirects. This forwarding happens regardless of changes in host, port, or protocol downgrade from HTTPS to HTTP, potentially leaking credentials to untrusted destinations. This issue is similar to a previously fixed problem in libcurl (CVE-2018-1000007).
Potential Impact
An attacker controlling or influencing redirects can cause sensitive authentication headers to be sent to unintended hosts, potentially exposing credentials. This leads to information disclosure without integrity or availability impact. The CVSS score of 5.9 reflects a medium severity due to the confidentiality impact and the requirement for network attacker capability with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid relying on redirects that could cause sensitive headers to be forwarded to untrusted hosts or downgrade protocols. Monitor vendor communications for official patches or workarounds.
CVE-2026-91766: CWE-200 in PHP Group PHP
Description
CVE-2026-91766 is a medium severity information disclosure vulnerability in PHP's http:// stream wrapper. When following redirects, it forwards user-supplied Authorization, Cookie, and Proxy-Authorization headers unchanged, even if the redirect target is a different host, port, or downgrades from HTTPS to HTTP. This can expose sensitive credentials to unintended servers.
CVSS v3.1
Score 5.9medium
Affected software
PHP Group
PHP
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability occurs in the PHP http:// stream wrapper where it improperly forwards sensitive headers such as Authorization, Cookie, and Proxy-Authorization when following HTTP redirects. This forwarding happens regardless of changes in host, port, or protocol downgrade from HTTPS to HTTP, potentially leaking credentials to untrusted destinations. This issue is similar to a previously fixed problem in libcurl (CVE-2018-1000007).
Potential Impact
An attacker controlling or influencing redirects can cause sensitive authentication headers to be sent to unintended hosts, potentially exposing credentials. This leads to information disclosure without integrity or availability impact. The CVSS score of 5.9 reflects a medium severity due to the confidentiality impact and the requirement for network attacker capability with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid relying on redirects that could cause sensitive headers to be forwarded to untrusted hosts or downgrade protocols. Monitor vendor communications for official patches or workarounds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- php
- Date Reserved
- 2026-09-15T00:38:24.146Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab6de10f7a7c5410644cf35
Added to database: 09/25/2026, 20:48:16 UTC
Last enriched: 09/25/2026, 21:02:50 UTC
Last updated: 09/25/2026, 21:16:29 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.