CVE-2026-33182: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33182 is a Server-Side Request Forgery (SSRF) and credential leakage vulnerability in the Saloon PHP HTTP client library (saloonphp/saloon). When building a request URL, Saloon's URLHelper::join() would use an absolute URL supplied as the endpoint as-is, completely ignoring the connector's configured base URL — along with any authentication headers, cookies, or tokens — and forwarding the request to the attacker-controlled host. All versions of the Composer package saloonphp/saloon prior to 4.0.0 are affected. The vulnerability was published on March 25, 2026, with a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.6 (Medium) (Github Advisory, Saloon Advisory).

Technical details

The root cause is improper URL construction logic in URLHelper::join(), classified under CWE-918 (Server-Side Request Forgery) and CWE-522 (Insufficiently Protected Credentials). When a request's resolveEndpoint() method returns a fully qualified absolute URL, Saloon's URL builder treats it as the final destination rather than appending it to the connector's base URL, effectively bypassing all base URL restrictions. This is exploitable when user-supplied or externally influenced data (e.g., redirect_uri, callback URLs, or configuration values) is passed into resolveEndpoint() without validation. The fix in v4.0.0 causes URLHelper::join() to throw an InvalidArgumentException when the endpoint is an absolute URL, unless the connector or request explicitly opts in to this behavior (Github Advisory, Saloon Advisory).

Impact

Successful exploitation allows an attacker to redirect server-side HTTP requests — including all attached authentication headers, API tokens, cookies, and OAuth credentials — to an attacker-controlled host, resulting in credential theft and unauthorized data exposure. The confidentiality impact is rated High, as sensitive authentication material can be exfiltrated without any integrity or availability impact to the vulnerable system itself. Applications that pass user-controlled values (such as OAuth redirect_uri or webhook callback URLs) into Saloon request endpoints are most at risk, and stolen credentials could enable further lateral movement into downstream APIs or services (Github Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-33182. The EPSS score is approximately 0.026–0.032%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that user-controlled or externally influenced input reaches the resolveEndpoint() method of a Saloon request, which is an application-level precondition rather than a universally exploitable condition (Github Advisory, Saloon Advisory).

Exploitation steps

  1. Identify a vulnerable application: Locate a PHP application using saloonphp/saloon < 4.0.0 that passes user-supplied or externally influenced data (e.g., redirect_uri, callback URL, webhook URL) into a Saloon request's resolveEndpoint() method.
  2. Set up a listener: Stand up an attacker-controlled HTTPS server (e.g., using ngrok, requestbin, or a VPS) capable of logging incoming HTTP requests and headers.
  3. Craft a malicious absolute URL payload: Prepare an absolute URL pointing to the attacker-controlled host, e.g., https://attacker.example.com/capture.
  4. Inject the payload: Supply the malicious absolute URL as the endpoint value through the vulnerable input vector (e.g., submit it as a redirect_uri or callback URL parameter in the application's API or configuration).
  5. Trigger the Saloon request: Cause the application to execute the Saloon request that uses the injected endpoint. Saloon's URLHelper::join() will use the absolute URL as-is, ignoring the connector's base URL.
  6. Capture credentials: Observe the incoming request on the attacker-controlled server, which will contain all authentication headers, API tokens, cookies, or OAuth tokens that the Saloon connector attaches to outbound requests (Github Advisory, Saloon Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the application server to unexpected or external hosts not matching the configured Saloon connector base URL; requests to attacker-controlled domains carrying Authorization, Cookie, or custom API token headers.
  • Logs: Application or web server logs showing HTTP requests being made to domains outside the expected API base URL; error logs referencing URLHelper::join() or InvalidArgumentException (post-patch, indicating attempted exploitation).
  • Application Behavior: Unexpected OAuth token or API key usage originating from third-party hosts; authentication failures on legitimate APIs due to token reuse or invalidation after credential theft.

Mitigation and workarounds

The primary remediation is to upgrade saloonphp/saloon to version 4.0.0 or later, which rejects absolute URLs in the endpoint by default and requires explicit opt-in on a per-connector or per-request basis (Github Advisory). The upgrade guide is available at https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4. As a workaround for applications that cannot immediately upgrade, developers should validate and sanitize all user-supplied input before passing it to resolveEndpoint(), explicitly rejecting any values that are valid absolute URLs. Additionally, review all Saloon connectors and requests that accept external or user-controlled endpoint values and apply allowlist-based URL validation.

Community reactions

The vulnerability was discovered by researcher @HuajiHD, who also recommended solutions, with the fix applied by @JonPurvis and verified by Saloon maintainer @Sammyjo20. The advisory was published directly by the Saloon project on GitHub on March 25, 2026. No significant broader media coverage or notable community controversy has been identified beyond the standard advisory distribution (Saloon Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management