CVE-2026-55824: Contao crawler leaks auth credentials to external hosts
Summary Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basicauth and bearerauth instead of Symfony HttpClient's real authbasic and authbearer options.
When contao.crawl.defaulthttpclientoptions contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials.
Technical Detail
Root Cause
php // core-bundle/src/Crawl/Escargot/Factory.php:175-209 @ e550b92a01ef625bd546e6c3956dd200af05ebf0 private function createHttpClient(array $options = []): HttpClientInterface { $options = arraymergerecursive( [ 'headers' => [ 'accept' => 'text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8', 'user-agent' => self::USERAGENT, ], 'maxduration' => 10, ], arraymergerecursive($this->getDefaultHttpClientOptions(), $options), );
$cleanOptions = $this->cleanOptionsFromConfidentialData($options);
if ($options === $cleanOptions) { return ($this->httpClientFactory)($options); }
$scopedOptionsByRegex = [];
foreach ($this->getRootPageUriCollection()->all() as $rootPageUri) { $scopedOptionsByRegex[pregquote($this->getOriginFromUri($rootPageUri))] = $options; }
return new ScopingHttpClient(($this->httpClientFactory)($cleanOptions), $scopedOptionsByRegex); }
php // core-bundle/src/Crawl/Escargot/Factory.php:226-247 @ e550b92a01ef625bd546e6c3956dd200af05ebf0 foreach ($options as $k => $v) { if ('headers' === $k) { foreach ($v as $header => $value) { if (\inarray(strtolower($header), ['authorization', 'cookie'], true)) { continue; }
$cleanOptions['headers'][$header] = $value; }
continue; }
if ('basicauth' === $k || 'bearerauth' === $k) { continue; }
$cleanOptions[$k] = $v; }
Symfony HttpClient authentication options are authbasic and authbearer; Contao's own manual documents authbasic for crawler Basic Authentication. Because the cleaner only strips basicauth and bearerauth, the "clean" default client for non-root-page hosts still carries the real auth options. The existing factory test intends to assert that Authorization is not sent to www.foreign-domain.com, but its mock client factory ignores the $defaultOptions argument, so it does not catch auth options that survive into HttpClient::create($cleanOptions).
Suggested Mitigation
Strip the actual Symfony HttpClient authentication option keys from the clean client. Include NTLM as a defensive extension because Symfony documents it as another auth option.
diff - if ('basicauth' === $k || 'bearerauth' === $k) { + if (\inarray($k, ['authbasic', 'authbearer', 'authntlm', 'basicauth', 'bearerauth'], true)) { continue; }
Also update the factory test so the mock factory records or preserves $defaultOptions; otherwise the test does not verify what HttpClient::create($cleanOptions) receives in production.
Impact
- Direct primitive: disclosure of crawler Basic/Bearer credentials to an external host reached by the crawler. - Chain potential: if those credentials protect a staging or pre-publication environment, an attacker can use them to access that environment. The impact depends on what the leaked credential unlocks. - Realistic exploitation: a content editor adds a link to https://attacker.example/probe on a page that the crawler visits. When an administrator or scheduled maintenance run starts the broken-link checker with crawler Basic/Bearer authentication configured, the request to the attacker URL includes the generated Authorization header.
Other sources
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basicauth and bearerauth instead of Symfony HttpClient's real authbasic and authbearer options. When contao.crawl.defaulthttpclientoptions contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.7.7 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.3.47 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 5.7.7 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 5.3.47 - Upgrade
Upgrade
Contao crawlerto a version that resolves this vulnerability.Fixed in 5.3.47 - Upgrade
Upgrade
Contao crawlerto a version that resolves this vulnerability.Fixed in 5.7.7 - Configuration
In contao.crawl.default_http_client_options, ensure no Basic or Bearer authentication is configured for staging/production credentials that must not be reused for external hosts (broken-link checker/external links).
Contao contao.crawl.default_http_client_options = (remove/avoid) Basic or Bearer authentication credentials - Configuration
Update the crawler cleaner behavior so the clean (non-root-page) HttpClient does not retain Symfony HttpClient authentication option keys; specifically, strip auth_basic and auth_bearer (and defensive extension: include auth_ntlm in the list of auth keys to strip).
Contao crawler (HttpClient options cleaner) cleaned auth option keys = Strip Symfony HttpClient auth options auth_basic and auth_bearer from the scoped/clean client - Configuration
Include NTLM as a defensive extension: strip auth_ntlm as well as auth_basic and auth_bearer from the clean client.
Contao crawler (HttpClient options cleaner) removed option keys (defensive extension) = Include NTLM - Compensating control
If you must run the broken-link checker while crawler credentials are configured, ensure attacker-controlled external URLs cannot be crawled (e.g., block or strictly control externally reachable URLs that the crawler would follow).
- Operational
After upgrading to a fixed Contao version, rotate any Basic/Bearer credentials that may have been exposed to external hosts via crawler requests.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55824?
The severity of CVE-2026-55824 is rated as low with a score of 2.6.
How do I fix CVE-2026-55824?
To address CVE-2026-55824, update your Contao installation to versions beyond 5.3.46 or 5.7.6.
What are the implications of CVE-2026-55824?
CVE-2026-55824 allows the Contao crawler to leak authentication credentials to external hosts, posing a potential security risk.
What versions of Contao are affected by CVE-2026-55824?
CVE-2026-55824 affects Contao versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6.
Is there any user interaction required for CVE-2026-55824 to be exploited?
Yes, CVE-2026-55824 requires user interaction as the exploitation depends on the crawler's operations.