Description
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.
Published: 2026-07-31
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Contao’s crawler inadvertently exposes authentication credentials to external hosts. The crawler’s logic purges Cookie and Authorization headers correctly, but mistakenly retains the raw basic_auth and bearer_auth option names instead of the Symfony HttpClient’s auth_basic and auth_bearer options. As a result, when the crawler is configured with Basic or Bearer authentication for protected sites, those credentials are sent on the “clean” client used for external links or additional URIs. This constitutes an information‑disclosure flaw (CWE-200) that can reveal user credentials to malicious parties.

Affected Systems

The vulnerability affects the Contao CMS for version ranges 4.13.40 through 5.3.46 and 5.7.0‑RC1 through 5.7.6. The issue was remediated in Contao 5.3.47 and in 5.7.7.

Risk and Exploitability

The CVSS score of 2.6 indicates low severity, and the EPSS score is reported as less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must be able to trigger the crawler to request an external URL, for example by placing a link on a crawled page while the broken‑link checker feature is active. When that occurs, the crawler sends the compromised credentials to the external host, enabling credential theft.

Generated by OpenCVE AI on August 2, 2026 at 03:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Contao to version 5.3.47 or later, or to 5.7.7 or later, where the bug has been fixed.
  • Disable the crawler’s broken‑link checker or restrict it so that it does not follow external links.
  • Remove or clear Basic and Bearer authentication settings from contao.crawl.default_http_client_options, or limit the crawler to internal domains only.

Generated by OpenCVE AI on August 2, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3mr9-p497-58f6 Contao crawler leaks auth credentials to external hosts
History

Fri, 31 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options. When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials. This issue has been fixed in versions 5.3.47 and 5.7.7.
Title Contao crawler leaks auth credentials to external hosts
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-31T19:58:42.933Z

Reserved: 2026-06-17T16:29:38.864Z

Link: CVE-2026-55824

cve-icon Vulnrichment

Updated: 2026-07-31T19:58:29.393Z

cve-icon NVD

Status : Received

Published: 2026-07-31T19:17:11.090

Modified: 2026-07-31T20:16:52.233

Link: CVE-2026-55824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T04:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor