CVE-2026-55824: Contao crawler leaks auth credentials to external hosts

Published Jul 31, 2026
·
Updated

Summary Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basicauth and bearerauth instead of Symfony HttpClient's real authbasic and authbearer options.

When contao.crawl.defaulthttpclientoptions contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials.

Technical Detail

Root Cause

php // core-bundle/src/Crawl/Escargot/Factory.php:175-209 @ e550b92a01ef625bd546e6c3956dd200af05ebf0 private function createHttpClient(array $options = []): HttpClientInterface { $options = arraymergerecursive( [ 'headers' => [ 'accept' => 'text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8', 'user-agent' => self::USERAGENT, ], 'maxduration' => 10, ], arraymergerecursive($this->getDefaultHttpClientOptions(), $options), );

$cleanOptions = $this->cleanOptionsFromConfidentialData($options);

if ($options === $cleanOptions) { return ($this->httpClientFactory)($options); }

$scopedOptionsByRegex = [];

foreach ($this->getRootPageUriCollection()->all() as $rootPageUri) { $scopedOptionsByRegex[pregquote($this->getOriginFromUri($rootPageUri))] = $options; }

return new ScopingHttpClient(($this->httpClientFactory)($cleanOptions), $scopedOptionsByRegex); }

php // core-bundle/src/Crawl/Escargot/Factory.php:226-247 @ e550b92a01ef625bd546e6c3956dd200af05ebf0 foreach ($options as $k => $v) { if ('headers' === $k) { foreach ($v as $header => $value) { if (\inarray(strtolower($header), ['authorization', 'cookie'], true)) { continue; }

$cleanOptions['headers'][$header] = $value; }

continue; }

if ('basicauth' === $k || 'bearerauth' === $k) { continue; }

$cleanOptions[$k] = $v; }

Symfony HttpClient authentication options are authbasic and authbearer; Contao's own manual documents authbasic for crawler Basic Authentication. Because the cleaner only strips basicauth and bearerauth, the "clean" default client for non-root-page hosts still carries the real auth options. The existing factory test intends to assert that Authorization is not sent to www.foreign-domain.com, but its mock client factory ignores the $defaultOptions argument, so it does not catch auth options that survive into HttpClient::create($cleanOptions).

Suggested Mitigation

Strip the actual Symfony HttpClient authentication option keys from the clean client. Include NTLM as a defensive extension because Symfony documents it as another auth option.

diff - if ('basicauth' === $k || 'bearerauth' === $k) { + if (\inarray($k, ['authbasic', 'authbearer', 'authntlm', 'basicauth', 'bearerauth'], true)) { continue; }

Also update the factory test so the mock factory records or preserves $defaultOptions; otherwise the test does not verify what HttpClient::create($cleanOptions) receives in production.

Impact

- Direct primitive: disclosure of crawler Basic/Bearer credentials to an external host reached by the crawler. - Chain potential: if those credentials protect a staging or pre-publication environment, an attacker can use them to access that environment. The impact depends on what the leaked credential unlocks. - Realistic exploitation: a content editor adds a link to https://attacker.example/probe on a page that the crawler visits. When an administrator or scheduled maintenance run starts the broken-link checker with crawler Basic/Bearer authentication configured, the request to the attacker URL includes the generated Authorization header.

Other sources

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basicauth and bearerauth instead of Symfony HttpClient's real authbasic and authbearer options. When contao.crawl.defaulthttpclientoptions contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.

— NVD

Affected Software

5 affected componentsFixes available
Contao Contao>=4.13.40<=5.3.46, >=5.7.0-RC1<=5.7.6
composer/contao/core-bundle>=5.4.0<5.7.7
5.7.7
composer/contao/core-bundle>=4.13.0<5.3.47
5.3.47
composer/contao/contao>=5.4.0<5.7.7
5.7.7
composer/contao/contao>=4.13.0<5.3.47
5.3.47

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/contao/core-bundle to a version that resolves this vulnerability.

    Fixed in 5.7.7
  2. Upgrade

    Upgrade composer/contao/core-bundle to a version that resolves this vulnerability.

    Fixed in 5.3.47
  3. Upgrade

    Upgrade composer/contao/contao to a version that resolves this vulnerability.

    Fixed in 5.7.7
  4. Upgrade

    Upgrade composer/contao/contao to a version that resolves this vulnerability.

    Fixed in 5.3.47
  5. Upgrade

    Upgrade Contao crawler to a version that resolves this vulnerability.

    Fixed in 5.3.47
  6. Upgrade

    Upgrade Contao crawler to a version that resolves this vulnerability.

    Fixed in 5.7.7
  7. Configuration

    In contao.crawl.default_http_client_options, ensure no Basic or Bearer authentication is configured for staging/production credentials that must not be reused for external hosts (broken-link checker/external links).

    Contao contao.crawl.default_http_client_options = (remove/avoid) Basic or Bearer authentication credentials
  8. Configuration

    Update the crawler cleaner behavior so the clean (non-root-page) HttpClient does not retain Symfony HttpClient authentication option keys; specifically, strip auth_basic and auth_bearer (and defensive extension: include auth_ntlm in the list of auth keys to strip).

    Contao crawler (HttpClient options cleaner) cleaned auth option keys = Strip Symfony HttpClient auth options auth_basic and auth_bearer from the scoped/clean client
  9. Configuration

    Include NTLM as a defensive extension: strip auth_ntlm as well as auth_basic and auth_bearer from the clean client.

    Contao crawler (HttpClient options cleaner) removed option keys (defensive extension) = Include NTLM
  10. Compensating control

    If you must run the broken-link checker while crawler credentials are configured, ensure attacker-controlled external URLs cannot be crawled (e.g., block or strictly control externally reachable URLs that the crawler would follow).

  11. Operational

    After upgrading to a fixed Contao version, rotate any Basic/Bearer credentials that may have been exposed to external hosts via crawler requests.

Event History

Jul 31, 2026
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Aug 6, 2026
Advisory Published
via GitHub·07:43 PM
Data Sourced
via GitHub·07:43 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55824?

The severity of CVE-2026-55824 is rated as low with a score of 2.6.

2

How do I fix CVE-2026-55824?

To address CVE-2026-55824, update your Contao installation to versions beyond 5.3.46 or 5.7.6.

3

What are the implications of CVE-2026-55824?

CVE-2026-55824 allows the Contao crawler to leak authentication credentials to external hosts, posing a potential security risk.

4

What versions of Contao are affected by CVE-2026-55824?

CVE-2026-55824 affects Contao versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6.

5

Is there any user interaction required for CVE-2026-55824 to be exploited?

Yes, CVE-2026-55824 requires user interaction as the exploitation depends on the crawler's operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203