PHP Patch Prevents Credentials From Being Sent to Rogue Servers

PHP has addressed a flaw in how its HTTP stream wrapper handles redirects—one that could inadvertently send private login credentials and cookies to malicious destinations. The issue, identified as CVE-2026-91766 (GHSA-fpwc-w8rq-cr92), was rated as having moderate severity. It comes into play when PHP apps use the http:// or https:// stream wrapper to fetch remote resources and automatically follow redirect responses.

The vulnerability allows sensitive request headers—think Authorization, Cookie, or Proxy-Authorization—to travel across redirect boundaries without verifying whether the new location is still part of the trusted origin. In practice, that means data meant for the original server, like bearer tokens, session cookies, or proxy credentials, could leak to an attacker if a redirect leads to a compromised or hostile domain, or if a redirect moves from HTTPS to HTTP or changes the port.

How It Was Exploitable

The risk mostly comes from PHP functions such as file_get_contents, fopen, readfile, or custom HTTP stream usage. If such a function makes a call attaching sensitive headers, and the remote server responds with a redirect under attacker control—or influenced by one—the client could unintentionally forward those secrets.

An attacker gains leverage if they can control the redirect response—via a third-party service, a manipulated URL the app calls, or by steering the redirect chain. No breach of the original server is needed in every scenario; the core issue is the trust boundary break that the redirect causes.

Fix and Recommended Mitigations

Maintainers have updated the behavior of the HTTP stream wrapper in supported PHP branches so that headers with sensitive data won’t slip through unsafe redirect paths. Developers are urged to upgrade to versions that include the fix as soon as possible. Security teams should also audit any code that sends authenticated HTTP requests and limit exposure of credentials on requests to untrusted URLs.

Best practices include verifying redirect destinations before you follow them, forbidding HTTPS-to-HTTP downgrades, and avoiding indiscriminate attachment of reusable credentials in outgoing requests. Especially important is ensuring that port and host changes in redirects don’t open a backdoor for credential leakage.

While the likelihood of this flaw being exploited depends on specific conditions—redirects, sensitive headers, attacker influence—the potential fallout is serious. Leaked session cookies or tokens can allow access to APIs, accounts, or cloud infrastructure that should remain off-limits.

This bug highlights a broader tension in web development between convenience and security. Automatically following redirects whilst attaching sensitive headers may’ve seemed benign, but the evolution of multi-domain apps, microservices, and complex redirect chains makes once-safe assumptions hazardous. It’s a reminder that trust must be earned and upheld at each step.