UPSTREAM FIX

magento2-40874: AJAX customer login failing on PHP 8.5 when captcha_form_id is missing

Community fix magento2-40874 merged into magento/magento2 on 2026-07-17, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.

Fixes AJAX customer login failing on PHP 8.5 when captcha_form_id is missing edited

Pull request title
Fix PHP 8.5 deprecation: Using null as the key parameter for array_key_exists()
Pull request
magento/magento2#40874
Issues
#40875 pr-derived
Author
@dimadidr
Merged
2026-07-17
Fixed in
no release yet
Reported on
2.4.9
Categories
Customer
Components
magento/module-captcha

Labels

Area
Account
Component
Login
Priority
P1
Severity
—
Reported on (labels)
2.4.9

Issue

Title and steps come from the upstream issue and pull request.

Description

On PHP 8.5, an AJAX customer login (e.g. the "Checkout using your account" sign-in popup) fails with "Could not authenticate. Please try again later" and the following deprecation is logged as report.CRITICAL:
[2026-06-11T19:13:56.998006+00:00] report.CRITICAL: Exception: Deprecated Functionality: Using null as the key parameter for array_key_exists() is deprecated, use an empty s
tring instead in /var/www/vendor/magento/module-captcha/Helper/Data.php on line 92 in /var/www/vendor/magento/framework/App/ErrorHandler.php:61
Stack trace:
#0 [internal function]: Magento\Framework\App\ErrorHandler->handler(8192, 'Using null as t...', '/var/www/vendor...', 92)
#1 /var/www/vendor/magento/module-captcha/Helper/Data.php(92): array_key_exists(NULL, Array)
#2 /var/www/vendor/magento/module-captcha/Model/Customer/Plugin/AjaxLogin.php(94): Magento\Captcha\Helper\Data->getCaptcha(NULL)
#3 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\Captcha\Model\Customer\Plugin\AjaxLogin->aroundExecute(Object(Magento\Customer\Controller\Aja
x\Login\Interceptor), Object(Closure))
#4 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Customer\Controller\Ajax\Login\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}()
#5 /var/www/generated/code/Magento/Customer/Controller/Ajax/Login/Interceptor.php(23): Magento\Customer\Controller\Ajax\Login\Interceptor->___callPlugins('execute', Array, N
ULL)
#6 /var/www/vendor/magento/framework/App/Action/Action.php(111): Magento\Customer\Controller\Ajax\Login\Interceptor->execute()
#7 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\Action\Action->dispatch(Object(Magento\Framework\App\Request\Http))
#8 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Customer\Controller\Ajax\Login\Interceptor->___callParent('dispatch', Array)
#9 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Customer\Controller\Ajax\Login\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#10 /var/www/generated/code/Magento/Customer/Controller/Ajax/Login/Interceptor.php(32): Magento\Customer\Controller\Ajax\Login\Interceptor->___callPlugins('dispatch', Array,
 Array)
#11 /var/www/vendor/magento/framework/App/FrontController.php(245): Magento\Customer\Controller\Ajax\Login\Interceptor->dispatch(Object(Magento\Framework\App\Request\Http))
#12 /var/www/vendor/magento/framework/App/FrontController.php(212): Magento\Framework\App\FrontController->getActionResponse(Object(Magento\Customer\Controller\Ajax\Login\In
terceptor), Object(Magento\Framework\App\Request\Http))
#13 /var/www/vendor/magento/framework/App/FrontController.php(146): Magento\Framework\App\FrontController->processRequest(Object(Magento\Framework\App\Request\Http), Object(
Magento\Customer\Controller\Ajax\Login\Interceptor))
#14 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\FrontController->dispatch(Object(Magento\Framework\App\Request\Http))
#15 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Framework\App\FrontController\Interceptor->___callParent('dispatch', Array)
#16 /var/www/vendor/magento/module-store/App/FrontController/Plugin/RequestPreprocessor.php(99): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framewor
k\Interception\Interceptor::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#17 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\Store\App\FrontController\Plugin\RequestPreprocessor->aroundDispatch(Object(Magento\Framewor
k\App\FrontController\Interceptor), Object(Closure), Object(Magento\Framework\App\Request\Http))
#18 /var/www/vendor/magento/module-page-cache/Model/App/FrontController/BuiltinPlugin.php(72): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framework\
Interception\Interceptor::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#19 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\PageCache\Model\App\FrontController\BuiltinPlugin->aroundDispatch(Object(Magento\Framework\A
pp\FrontController\Interceptor), Object(Closure), Object(Magento\Framework\App\Request\Http))
#20 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#21 /var/www/generated/code/Magento/Framework/App/FrontController/Interceptor.php(23): Magento\Framework\App\FrontController\Interceptor->___callPlugins('dispatch', Array, N
ULL)
#22 /var/www/vendor/magento/framework/App/Http.php(116): Magento\Framework\App\FrontController\Interceptor->dispatch(Object(Magento\Framework\App\Request\Http))
#23 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\Http->launch()
#24 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Framework\App\Http\Interceptor->___callParent('launch', Array)
#25 /var/www/vendor/magento/module-application-performance-monitor/Plugin/ApplicationPerformanceMonitor.php(38): Magento\Framework\App\Http\Interceptor->{closure:Magento\Fra
mework\Interception\Interceptor::___callPlugins():104}()
#26 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\ApplicationPerformanceMonitor\Plugin\ApplicationPerformanceMonitor->aroundLaunch(Object(Mage
nto\Framework\App\Http\Interceptor), Object(Closure))
#27 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Framework\App\Http\Interceptor->{closure:Magento\Framework\Interception\Interceptor::___call
Plugins():104}()
#28 /var/www/generated/code/Magento/Framework/App/Http/Interceptor.php(23): Magento\Framework\App\Http\Interceptor->___callPlugins('launch', Array, NULL)
#29 /var/www/vendor/magento/framework/App/Bootstrap.php(264): Magento\Framework\App\Http\Interceptor->launch()
#30 /var/www/pub/index.php(30): Magento\Framework\App\Bootstrap->run(Object(Magento\Framework\App\Http\Interceptor))
#31 {main} {"report_id":"2ae3a657eaf9a9217bb256096f1da0896e4ce0d7afe08a8200685c8aa1283a3d","exception":"[object] (Exception(code: 0): Deprecated Functionality: Using null as
 the key parameter for array_key_exists() is deprecated, use an empty string instead in /var/www/vendor/magento/module-captcha/Helper/Data.php on line 92 at /var/www/vendor/
magento/framework/App/ErrorHandler.php:61)"} []
<img width="1920" height="1080" alt="image" src="https://github.com/user-attachments/assets/500b817f-0a61-4f84-9d36-cf0f32b012c2" />

Steps to reproduce

1. Run Magento on PHP 8.5
2. Go to Stores > Configuration > Sales > Checkout > Checkout Options and set Allow Guest Checkout to No, then flush the cache
3. Make sure CAPTCHA for the user_login form is not forced (default config)
4. As a not-logged-in customer, add a product to the cart and proceed to checkout — the "Checkout as a new customer / Checkout using your account" popup appears
5. In the "Checkout using your account" block, enter the credentials of an existing customer and click Sign In
6. Before the fix: the request fails with "Could not authenticate. Please try again later", and var/report/var/log contains `report.CRITICAL: Exception: Deprecated
Functionality: Using null as the key parameter for array_key_exists() ... in module-captcha/Helper/Data.php on line 92`
7. After the fix: the customer signs in successfully and no deprecation is logged

Taken from the upstream pull request.

Error signatures

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: fails before, passes afterunit: fails before, passes after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: fails before, passes afterunit: fails before, passes after
2.4.9
2.4.9 clean
2.4.9: fails before, passes afterunit: fails before, passes after

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 95.9%. Probability it is security relevant: 80.1%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 91.3%, refactor 3.2%, dependency 2.5%, tests_only 1.2%, feature 1.2%, docs_only 0.7%80.1%
Areacustomercustomer 86.3%, checkout 7.6%, other 1.8%71.5%
Reported version2.4.92.4.9 30.8%, unspecified 10.8%, 2.4.8 2.2%10.1%
Scope0.77 of 21 57.7%, 0 32.5%, 2 9.8%17.2%
Risk0.87 of 20 49.0%, 2 36.4%, 1 14.5%9.1%
Worth backporting1.43 of 22 57.6%, 1 27.5%, 0 14.9%14.4%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40874/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-captcha
Bundle README (what the ZIP ships)
# magento2-40874

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40874
Issue: https://github.com/magento/magento2/issues/40875
Author: @dimadidr
Source commit: 0f74fbbef2f777ba8e61c8b211ded1aefb784db1
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.