CVE-2026-91766 links PHP redirects to credential exposure
An r/PHP post points to CVE-2026-91766 and associates it with a credential leak during HTTP redirects in PHP. The headline also notes that curl addressed the same redirect-related issue in 2018. The source provides no affected PHP versions, patch information, severity rating, or reproduction details.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.