AZL-104916

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104916.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-104916
Upstream
  • CVE-2026-91766
Published
2026-09-25T21:17:24Z
Modified
2026-09-26T14:16:17Z
Summary
CVE-2026-91766 affecting package php 8.3.33-1
Details

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

References

Affected packages

Azure Linux:3 / php

Package

Name
php
Purl
pkg:rpm/azure-linux/php

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.3.33-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104916.json"