Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist

GHSA-3mr9-p497-58f6

LOW

GHSA-3mr9-p497-58f6 is a low-severity (CVSS 2.6) Information Exposure vulnerability in contao/contao. O3 Security confirms whether GHSA-3mr9-p497-58f6 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

Contao crawler leaks auth credentials to external hosts

Also known asCVE-2026-55824
Published
Aug 6, 2026
Updated
Aug 6, 2026
Affected
4 pkgs
Patched
4 / 4
Exploits
None indexed

Blast Radius

4 pkgs affected
🐘contao/contao🐘contao/contao🐘contao/core-bundle🐘contao/core-bundle

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Summary

Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony HttpClient's real auth_basic and auth_bearer options.

When contao.crawl.default_http_client_options contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" client used for external links or configured additional URIs. An attacker who can get an external URL crawled, for example through a link on a crawled page while the broken-link checker is enabled, can receive the crawler credentials.

Technical Detail

Root Cause

// core-bundle/src/Crawl/Escargot/Factory.php:175-209 @ e550b92a01ef625bd546e6c3956dd200af05ebf0
private function createHttpClient(array $options = []): HttpClientInterface
{
    $options = array_merge_recursive(
        [
            'headers' => [
                'accept' => 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8',
                'user-agent' => self::USER_AGENT,
            ],
            'max_duration' => 10,
        ],
        array_merge_recursive($this->getDefaultHttpClientOptions(), $options),
    );

    $cleanOptions = $this->cleanOptionsFromConfidentialData($options);

    if ($options === $cleanOptions) {
        return ($this->httpClientFactory)($options);
    }

    $scopedOptionsByRegex = [];

    foreach ($this->getRootPageUriCollection()->all() as $rootPageUri) {
        $scopedOptionsByRegex[preg_quote($this->getOriginFromUri($rootPageUri))] = $options;
    }

    return new ScopingHttpClient(($this->httpClientFactory)($cleanOptions), $scopedOptionsByRegex);
}
// core-bundle/src/Crawl/Escargot/Factory.php:226-247 @ e550b92a01ef625bd546e6c3956dd200af05ebf0
foreach ($options as $k => $v) {
    if ('headers' === $k) {
        foreach ($v as $header => $value) {
            if (\in_array(strtolower($header), ['authorization', 'cookie'], true)) {
                continue;
            }

            $cleanOptions['headers'][$header] = $value;
        }

        continue;
    }

    if ('basic_auth' === $k || 'bearer_auth' === $k) {
        continue;
    }

    $cleanOptions[$k] = $v;
}

Symfony HttpClient authentication options are auth_basic and auth_bearer; Contao's own manual documents auth_basic for crawler Basic Authentication. Because the cleaner only strips basic_auth and bearer_auth, the "clean" default client for non-root-page hosts still carries the real auth options. The existing factory test intends to assert that Authorization is not sent to www.foreign-domain.com, but its mock client factory ignores the $defaultOptions argument, so it does not catch auth options that survive into HttpClient::create($cleanOptions).

Suggested Mitigation

Strip the actual Symfony HttpClient authentication option keys from the clean client. Include NTLM as a defensive extension because Symfony documents it as another auth option.

-            if ('basic_auth' === $k || 'bearer_auth' === $k) {
+            if (\in_array($k, ['auth_basic', 'auth_bearer', 'auth_ntlm', 'basic_auth', 'bearer_auth'], true)) {
                 continue;
             }

Also update the factory test so the mock factory records or preserves $defaultOptions; otherwise the test does not verify what HttpClient::create($cleanOptions) receives in production.

Impact

  • Direct primitive: disclosure of crawler Basic/Bearer credentials to an external host reached by the crawler.
  • Chain potential: if those credentials protect a staging or pre-publication environment, an attacker can use them to access that environment. The impact depends on what the leaked credential unlocks.
  • Realistic exploitation: a content editor adds a link to https://attacker.example/probe on a page that the crawler visits. When an administrator or scheduled maintenance run starts the broken-link checker with crawler Basic/Bearer authentication configured, the request to the attacker URL includes the generated Authorization header.

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistcontao/contao4.13.0&&< 5.3.475.3.47
🐘Packagistcontao/contao5.4.0&&< 5.7.75.7.7
🐘Packagistcontao/core-bundle4.13.0&&< 5.3.475.3.47
🐘Packagistcontao/core-bundle5.4.0&&< 5.7.75.7.7

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for contao/contao. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update contao/contao to 5.3.47 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-3mr9-p497-58f6 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-3mr9-p497-58f6 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-3mr9-p497-58f6. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Summary Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes `Cookie` and `Authorization` headers, but it removes the non-Symfony option names `basic_auth` and `bearer_auth` instead of Symfony HttpClient's real `auth_basic` and `auth_bearer` options. When `contao.crawl.default_http_client_options` contains Basic or Bearer authentication for a protected staging/production site, those credentials remain in the "clean" cli
O3 Security · Impact-Aware SCA

Is GHSA-3mr9-p497-58f6 in your dependencies?

O3 detects GHSA-3mr9-p497-58f6 across Packagist dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.