A security vulnerability in PHP, identified as CVE-2026-91766 and tracked as GHSA-fpwc-w8rq-cr92, has been fixed This article explores security vulnerability php. . This flaw affects PHP's HTTP stream wrapper and could expose login credentials, cookies, and proxy authentication data to an unintended server during HTTP redirects.
Under vulnerable conditions, PHP forwards user-supplied sensitive request headers to the redirect destination without verifying that the destination remains the same trusted origin. PHP fixed a bug If the remote server responds with a redirect to a domain controlled by an attacker, older PHP versions could send the same authentication header to the attacker's domain. The flaw is particularly relevant for applications that retrieve external resources through PHP stream functions such as file_get_contents(), fopen(), readfile(), or custom code built around HTTP stream contexts.
PHP's advisory classifies the problem as a cross-origin credential leak, which means the redirected request moves beyond the original combination of scheme, host, and port. Developers should avoid attaching reusable credentials to requests for untrusted URLs, validate redirect destinations, restrict outbound connections where possible, and prevent HTTPS-to-HTTP downgrade redirects. A leaked bearer token or session cookie could allow an attacker to access internal APIs, cloud services, application accounts, or proxy infrastructure using credentials that were never intended to leave the original server.
Reduce SOC alert investigation time by 21 minutes.










