Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. contao/core-bundle
  4. ›
  5. CVE-2026-55824

CVE-2026-55824: Contao crawler leaks auth credentials to external hosts

August 6, 2026

Contao’s crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient’s real auth_basic and auth_bearer options.

When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the “clean” client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials.

References

  • contao.org/en/security-advisories/credentials-disclosure-in-the-crawler
  • github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2026-55824.yaml
  • github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2026-55824.yaml
  • github.com/advisories/GHSA-3mr9-p497-58f6
  • github.com/contao/contao/commit/5bc6e3f900c439313df57aa561d0865792aafa05
  • github.com/contao/contao/commit/80425d28cdf66280a209bd3f5bc31b1a76901a04
  • github.com/contao/contao/security/advisories/GHSA-3mr9-p497-58f6
  • nvd.nist.gov/vuln/detail/CVE-2026-55824

Code Behaviors & Features

Detect and mitigate CVE-2026-55824 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.13.0 before 5.3.47, all versions starting from 5.4.0 before 5.7.7

Fixed versions

  • 5.3.47
  • 5.7.7

Solution

Upgrade to versions 5.3.47, 5.7.7 or above.

Impact 2.6 LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Source file

packagist/contao/core-bundle/CVE-2026-55824.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:16:47 +0000.