CVE-2026-91766 | PHP up to 8.2.33/8.3.34/8.4.25/8.5.10 http stream wrapper information disclosure
A vulnerability, which was classified as problematic, was found in PHP up to 8.2.33/8.3.34/8.4.25/8.5.10. This vulnerability affects unknown code of the component http stream wrapper. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-91766. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More