Insufficiently protected credentials in PHP - CVE-2026-91766
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose credentials.
The vulnerability exists due to improper credential forwarding in the HTTP stream wrapper when following a cross-origin redirect. A remote attacker can control a redirect target to disclose credentials.
The issue affects user-supplied Authorization, Cookie, and Proxy-Authorization headers, including redirects from HTTPS to HTTP.