CVE-2026-91766:
PHP 취약성 분석 및 완화
개요
CVE-2026-91766 is a cross-origin credential leak vulnerability in PHP's HTTP stream wrapper that causes authentication headers — including Authorization, Cookie, and Proxy-Authorization — to be forwarded unchanged when following HTTP redirects to a different host, port, or protocol. It affects PHP versions before 8.2.34, 8.3.35, 8.4.26, and 8.5.11, and was published on September 24, 2026. The vulnerability is analogous to the class of issue libcurl fixed in 7.58.0 (CVE-2018-1000007). It carries a CVSS v3.1 base score of 5.9 (Moderate) (GitHub Advisory).
기술적 세부 사항
The root cause lies in PHP's http_fopen_wrapper.c, where the HTTP stream wrapper strips only Content-Length and Content-Type headers before following a redirect, and only when the HTTP method changes — leaving credential headers intact regardless of whether the redirect target is a different origin (CWE-200, CWE-522). The wrapper passes no origin-awareness to the recursive redirect call, so headers supplied via stream_context_create() are carried into the redirected request verbatim. A redirect from HTTPS to HTTP additionally exposes credentials in cleartext on the network. The fix introduces an HTTP_WRAPPER_STRIP_AUTH flag that records the effective origin (scheme, host, port) and strips credential headers on any cross-origin hop, with the flag remaining sticky for all subsequent hops — mirroring libcurl's behavior with CURLOPT_UNRESTRICTED_AUTH disabled (GitHub Advisory, PHP NEWS).
영향
Any PHP application using file_get_contents(), fopen(), or other HTTP stream wrapper functions with credential headers and the default follow_location behavior is at risk of leaking bearer tokens, session cookies, or proxy credentials to unintended third-party servers. An attacker who controls a redirect target — or a legitimate service that redirects to a third party — can silently harvest these credentials. A redirect from HTTPS to HTTP additionally exposes the credentials in cleartext on the network, compounding the confidentiality impact (GitHub Advisory).
악용 가능성
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of disclosure. The GitHub advisory includes a conceptual PoC demonstrating that a 302 Found redirect from https://example.com/api to https://attacker.example/ causes the attacker's server to receive the Authorization: Bearer and Cookie headers. Exploitation requires the attacker to control or influence a redirect target, raising the attack complexity. The CVE status was listed as "Reserved" at the time of Feedly ingestion, and no EPSS score or CISA KEV listing has been identified (GitHub Advisory, Feedly).
착취 단계
- Set up a malicious redirect server: Configure a server (e.g.,
https://attacker.example/) to log all incoming HTTP headers, includingAuthorizationandCookie. - Control or influence a redirect: Either operate a service that issues a
302 Foundor301 Moved Permanentlyredirect to the attacker-controlled server, or compromise/manipulate a legitimate service that redirects to a third party. - Trigger the vulnerable PHP application: Cause the target PHP application to make an HTTP request using
file_get_contents(),fopen(), or a similar stream wrapper function with credential headers (e.g.,Authorization: Bearer SECRETorCookie: sid=abc) set viastream_context_create()andfollow_locationenabled (the default). - Receive leaked credentials: The PHP HTTP stream wrapper follows the redirect without stripping the credential headers, forwarding them to the attacker's server. The attacker's server logs the
Authorization,Cookie, and/orProxy-Authorizationheaders from the original request. - Exploit harvested credentials: Use the captured bearer token or session cookie to impersonate the victim application or user against the original service (GitHub Advisory).
타협의 징후
- Network: Outbound HTTP/HTTPS requests from the PHP application server to unexpected third-party hosts immediately following requests to a known API or service endpoint; HTTP requests to attacker-controlled domains carrying
AuthorizationorCookieheaders. - Logs: Web server or application logs showing HTTP 3xx redirect responses from a trusted service followed by outbound requests to a different domain with credential headers present; access logs on attacker-controlled servers showing inbound requests with
Authorization: BearerorCookieheaders originating from the PHP application's IP. - Application Behavior: Unexpected authentication failures or token invalidation events on the original service, potentially indicating credential reuse by a third party after interception.
완화 및 해결 방법
PHP has released patched versions addressing CVE-2026-91766: 8.2.34, 8.3.35, 8.4.26, and 8.5.11. Upgrading to one of these versions is the recommended remediation. As a workaround prior to patching, applications can disable automatic redirect following by setting follow_location to 0 in the stream context and implementing manual redirect handling that strips credential headers on cross-origin hops. Alternatively, use a dedicated HTTP client library (e.g., Guzzle with libcurl) that already handles cross-origin credential stripping correctly (GitHub Advisory, PHP NEWS).
커뮤니티 반응
The vulnerability attracted community discussion on Hacker News and Reddit's r/PHP shortly after disclosure, with users noting the similarity to the long-standing libcurl issue (CVE-2018-1000007) fixed in 2018. Security bloggers and the Remi repository maintainer highlighted the fix as part of the broader September 2026 PHP security release. Tenable's Nessus scanner added detection plugins for the vulnerability within days of disclosure (Hacker News, Reddit r/PHP, Remi Blog).
추가 자료
리눅스 배포판 수정 현황
주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.
bionic (esm-infra)
php7.2
devel
php8.5
focal (esm-infra)
php7.4
jammy
php8.1
noble
php8.3
resolute
php8.5
trusty (esm-infra-legacy)
php5
xenial (esm-infra-legacy)
php7.0
RHEL 8
php:7.4/php.src
RHEL 9
php.src
RHEL 10
php.src
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 PHP 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."