THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3mr9-p497-58f6 (low) — Contao crawler leaks auth credentials to external hosts

[GHSA] GHSA-3mr9-p497-58f6 (low) — Contao crawler leaks auth credentials to external hosts

highgithub_advisoriesPublished 2026-08-06

GHSA-3mr9-p497-58f6 Severity: low CVE: CVE-2026-55824

Contao crawler leaks auth credentials to external hosts

### Summary Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes `Cookie` and `Authorization` headers, but it remove

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3mr9-p497-58f6