PHP Fixed a Bug That Could Send Your Login Credentials to the Wrong Server

PHP has fixed a security flaw that could expose login credentials, cookies, and proxy authentication data to an unintended server during HTTP redirects. The vulnerability, tracked as CVE-2026-91766 and GHSA-fpwc-w8rq-cr92, affects PHP’s HTTP stream wrapper and has been rated as moderate severity. The issue occurs when a PHP application uses the http:// or https:// stream […]

This article has been indexed from Cyber Security News

Read the original article: