THREAT OPS › Threat News › [GHSA] GHSA-3mr9-p497-58f6 (low) — Contao crawler leaks auth credentials to external hosts
[GHSA] GHSA-3mr9-p497-58f6 (low) — Contao crawler leaks auth credentials to external hosts
GHSA-3mr9-p497-58f6 Severity: low CVE: CVE-2026-55824
Contao crawler leaks auth credentials to external hosts
### Summary Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes `Cookie` and `Authorization` headers, but it remove
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- e550b92a01ef625bd546e6c3956dd200af05ebf0sha1
- CVE-2026-55824cve
- https://attacker.example/probe`url
- www.foreign-domain.comdomain
Original source: https://github.com/advisories/GHSA-3mr9-p497-58f6