Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpwc-w8rq-cr92

Опубликовано: 24 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Cross-origin credential leak in HTTP stream wrapper redirects

Summary

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 (CVE-2018-1000007).

Details

Headers supplied through stream_context_create() are carried into the redirected request together with the rest of the context. Before the redirect is issued, the wrapper strips only Content-Length and Content-Type, and only when the method changes:

https://github.com/php/php-src/blob/php-8.5.10/ext/standard/http_fopen_wrapper.c#L703-L704

The flags handed to the recursive call carry no notion of the origin the credentials belong to:

https://github.com/php/php-src/blob/php-8.5.10/ext/standard/http_fopen_wrapper.c#L1133

The fix records the effective origin of the current request, being scheme, host and port with the default port filled in, and compares it with the parsed redirect target. When they differ, a new HTTP_WRAPPER_STRIP_AUTH flag is set and the three credential headers are removed from the user header bag before the next request is built. The flag is sticky, so credentials stay withheld for any further hops after a cross-origin one, matching libcurl's behaviour with CURLOPT_UNRESTRICTED_AUTH disabled.

Removing the last header from the bag also required strip_header() to drop the line break preceding it. Without that, the CRLF appended after the bag ends the header block early and the body of a body-preserving 307 or 308 redirect is corrupted. The same rewrite makes strip_header() scan line by line, so a repeated header, a folded continuation line, or the header name appearing inside another header's value can no longer leave the real header in place.

PoC

A request to https://example.com/api carrying Authorization: Bearer <token> that is answered with 302 Found to https://attacker.example/ results in the attacker's server receiving the Authorization header:

<?php $ctx = stream_context_create(['http' => [ 'header' => "Authorization: Bearer SECRET\r\nCookie: sid=abc", 'follow_location' => 1, ]]); file_get_contents('https://example.com/api', false, $ctx);

The regression test ext/standard/tests/http/ghsa-fpwc-w8rq-cr92.phpt runs two local servers on different ports and asserts that credentials are dropped on the cross-origin hop and on every hop after it, while being preserved when every hop stays on the same origin.

Impact

Any application that uses file_get_contents(), fopen() or another http:// stream with credential headers and leaves follow_location at its default is affected. An attacker who controls a redirect target, or a legitimate service that redirects to a third party, receives the bearer token, session cookie or proxy credentials of the caller. A redirect from HTTPS to HTTP additionally exposes them in cleartext on the network.

Пакеты

Наименование

php

php
Затронутые версииВерсия исправления

>=8.2.0, <8.2.34

8.2.34

Наименование

php

php
Затронутые версииВерсия исправления

>=8.3.0, <8.3.35

8.3.35

Наименование

php

php
Затронутые версииВерсия исправления

>=8.4.0, <8.4.26

8.4.26

Наименование

php

php
Затронутые версииВерсия исправления

>=8.5.0, <8.5.11

8.5.11

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 5.9
ubuntu
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
redhat
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
nvd
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
msrc
4 дня назад

Cross-origin credential leak in HTTP stream wrapper redirects

CVSS3: 5.9
debian
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the use ...

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200
CWE-522