---
id: CVE-2026-55824
title: Contao is an Open Source CMS
summary: >-
  Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1
  through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's
  crawler tries to prevent confidential HTTP client options from being sent to
  ext…
severity: low
cvss: 2.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: contao
product: contao/contao
affected:
  - 'contao/contao >= 4.13.0, < 5.3.47'
  - 'contao/contao >= 5.4.0, < 5.7.7'
  - 'contao/core-bundle >= 4.13.0, < 5.3.47'
  - 'contao/core-bundle >= 5.4.0, < 5.7.7'
patched:
  - contao/contao 5.3.47
  - contao/contao 5.7.7
  - contao/core-bundle 5.3.47
  - contao/core-bundle 5.7.7
published: '2026-07-31'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55824'
references:
  - url: 'https://github.com/contao/contao/security/advisories/GHSA-3mr9-p497-58f6'
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55824'
  - url: >-
      https://github.com/contao/contao/commit/5bc6e3f900c439313df57aa561d0865792aafa05
  - url: >-
      https://github.com/contao/contao/commit/80425d28cdf66280a209bd3f5bc31b1a76901a04
  - url: >-
      https://contao.org/en/security-advisories/credentials-disclosure-in-the-crawler
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2026-55824.yaml
  - url: >-
      https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2026-55824.yaml
  - url: 'https://github.com/advisories/GHSA-3mr9-p497-58f6'
tags:
  - nvd
  - ghsa
  - composer
epss: 0.00154
epssPercentile: 0.04952
aliases:
  - GHSA-3mr9-p497-58f6
ecosystem: composer
ingestedAt: '2026-08-06T20:03:56.502Z'
---

## Overview

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55824)

Affected packages:

- `contao/contao >= 4.13.0, < 5.3.47`
- `contao/contao >= 5.4.0, < 5.7.7`
- `contao/core-bundle >= 4.13.0, < 5.3.47`
- `contao/core-bundle >= 5.4.0, < 5.7.7`

Patched in:

- `contao/contao 5.3.47`
- `contao/contao 5.7.7`
- `contao/core-bundle 5.3.47`
- `contao/core-bundle 5.7.7`

Source: https://github.com/advisories/GHSA-3mr9-p497-58f6
