当 http:// 流包装器(stream wrapper)跟随重定向时,它会将用户提供的 Authorization、Cookie 和 Proxy-Authorization 头信息原样转发,即使重定向目标指向不同的主机、不同的端口,或者存在从 HTTPS 到 HTTP 的降级情况。因此,能够操控重定向的服务器会接收到原本仅意图发送给原始源站的凭据。此类问题与 libcurl 在版本 7.58.0 中修复的 CVE-2018-1000007(详见 https://github.com/advisories/GHS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91765 | 7.5 HIGH | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node |
| CVE-2026-17545 | 6.9 MEDIUM | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca |
| CVE-2026-91767 | 6.5 MEDIUM | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard |
| CVE-2026-91768 | 6.5 MEDIUM | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm |
| CVE-2025-14181 | 6.5 MEDIUM | Integer overflow to buffer overflow in soap HTTP parsing |
| CVE-2026-92842 | 5.9 MEDIUM | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL |
| CVE-2026-93682 | 5.8 MEDIUM | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca |
| CVE-2026-6103 | 4.3 MEDIUM | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection |
| CVE-2026-91769 | 4.3 MEDIUM | TLS Hostname Verification Falls Back to CN After SAN Mismatch |
| CVE-2025-1218 | 3.4 LOW | Various packet overreads in mysqlnd_writeprotocol.c |
No comments yet