• Sources: advisory, writeup, discussion
  • Summary: Any application that calls file_get_contents() or fopen() on an http:// stream with a credential header and leaves follow_location at its default sent that header to whatever host, port or downgraded scheme the redirect pointed at. CVE-2026-91766 is rated moderate at CVSS 5.9, affects PHP below 8.2.34, 8.3.35, 8.4.26 and 8.5.11, and is patched in those four releases, published 2026-09-24. The advisory states the fix records scheme, host and port for the current request, strips authorization, cookie and proxy-authorization on a cross-origin hop, and keeps them withheld on every later hop.
  • Why it matters: Secrets carried in a header of your own, such as X-Api-Key, are not stripped, so those callers still have to set follow_location to 0 and follow the redirect themselves.

send feedback on this story