CVE-2026-55824Low· 2.6▾ SunlitContao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to ext…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
contao/contao >= 4.13.0, < 5.3.47contao/contao >= 5.4.0, < 5.7.7contao/core-bundle >= 4.13.0, < 5.3.47contao/core-bundle >= 5.4.0, < 5.7.7Patched in:
contao/contao 5.3.47contao/contao 5.7.7contao/core-bundle 5.3.47contao/core-bundle 5.7.7Connected by shared product, vendor, weakness, or advisory.
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-47132Medium· 5.4phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
CVE-2026-50157Medium· 6.5Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module