by Leo Feyer

Credentials disclosure in the crawler

Date: 2026-06-15
CVE ID: CVE-2026-55824

If the crawler is set to crawl protected pages, it sends the authorization credentials to externals URLs.

Affected versions

Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.46
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.6

Suggested solution

Upgrade to Contao 5.3.47 or 5.7.7.

Workaround

Disable crawling protected pages.

More information

https://github.com/contao/contao/security/advisories/GHSA-3mr9-p497-58f6