Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91766

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

A flaw was found in PHP. When following a redirect, the built-in HTTP (Hypertext Transfer Protocol) stream wrapper forwards sensitive request headers—such as authentication tokens and session cookies—unchanged, even when directed to a different host, port, or unencrypted connection. A malicious server capable of steering redirects can exploit this flaw to capture sensitive credentials intended only for the original destination.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpFix deferred
Red Hat Enterprise Linux 10php8.4Fix deferred
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.4/phpFix deferred
Red Hat Enterprise Linux 8php:8.2/phpFix deferred
Red Hat Enterprise Linux 9phpFix deferred
Red Hat Enterprise Linux 9php:8.2/phpFix deferred
Red Hat Enterprise Linux 9php:8.3/phpFix deferred
Red Hat Enterprise Linux 9php:8.4/phpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2541649php: php: Credential disclosure via cross-origin HTTP redirects

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
nvd
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
msrc
4 дня назад

Cross-origin credential leak in HTTP stream wrapper redirects

CVSS3: 5.9
debian
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the use ...

CVSS3: 5.9
github
9 дней назад

Cross-origin credential leak in HTTP stream wrapper redirects

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3