magento2-40874: AJAX customer login failing on PHP 8.5 when captcha_form_id is missing
Community fix magento2-40874 merged into magento/magento2 on 2026-07-17, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.
Fixes AJAX customer login failing on PHP 8.5 when captcha_form_id is missing edited
- Pull request title
- Fix PHP 8.5 deprecation: Using null as the key parameter for array_key_exists()
- Pull request
- magento/magento2#40874
- Issues
- #40875 pr-derived
- Author
- @dimadidr
- Merged
- 2026-07-17
- Fixed in
- no release yet
- Reported on
- 2.4.9
- Categories
- Customer
- Components
- magento/module-captcha
Labels
- Area
- Account
- Component
- Login
- Priority
- P1
- Severity
- —
- Reported on (labels)
- 2.4.9
Issue
Title and steps come from the upstream issue and pull request.
Description
report.CRITICAL:[2026-06-11T19:13:56.998006+00:00] report.CRITICAL: Exception: Deprecated Functionality: Using null as the key parameter for array_key_exists() is deprecated, use an empty s
tring instead in /var/www/vendor/magento/module-captcha/Helper/Data.php on line 92 in /var/www/vendor/magento/framework/App/ErrorHandler.php:61
Stack trace:
#0 [internal function]: Magento\Framework\App\ErrorHandler->handler(8192, 'Using null as t...', '/var/www/vendor...', 92)
#1 /var/www/vendor/magento/module-captcha/Helper/Data.php(92): array_key_exists(NULL, Array)
#2 /var/www/vendor/magento/module-captcha/Model/Customer/Plugin/AjaxLogin.php(94): Magento\Captcha\Helper\Data->getCaptcha(NULL)
#3 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\Captcha\Model\Customer\Plugin\AjaxLogin->aroundExecute(Object(Magento\Customer\Controller\Aja
x\Login\Interceptor), Object(Closure))
#4 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Customer\Controller\Ajax\Login\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}()
#5 /var/www/generated/code/Magento/Customer/Controller/Ajax/Login/Interceptor.php(23): Magento\Customer\Controller\Ajax\Login\Interceptor->___callPlugins('execute', Array, N
ULL)
#6 /var/www/vendor/magento/framework/App/Action/Action.php(111): Magento\Customer\Controller\Ajax\Login\Interceptor->execute()
#7 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\Action\Action->dispatch(Object(Magento\Framework\App\Request\Http))
#8 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Customer\Controller\Ajax\Login\Interceptor->___callParent('dispatch', Array)
#9 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Customer\Controller\Ajax\Login\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#10 /var/www/generated/code/Magento/Customer/Controller/Ajax/Login/Interceptor.php(32): Magento\Customer\Controller\Ajax\Login\Interceptor->___callPlugins('dispatch', Array,
Array)
#11 /var/www/vendor/magento/framework/App/FrontController.php(245): Magento\Customer\Controller\Ajax\Login\Interceptor->dispatch(Object(Magento\Framework\App\Request\Http))
#12 /var/www/vendor/magento/framework/App/FrontController.php(212): Magento\Framework\App\FrontController->getActionResponse(Object(Magento\Customer\Controller\Ajax\Login\In
terceptor), Object(Magento\Framework\App\Request\Http))
#13 /var/www/vendor/magento/framework/App/FrontController.php(146): Magento\Framework\App\FrontController->processRequest(Object(Magento\Framework\App\Request\Http), Object(
Magento\Customer\Controller\Ajax\Login\Interceptor))
#14 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\FrontController->dispatch(Object(Magento\Framework\App\Request\Http))
#15 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Framework\App\FrontController\Interceptor->___callParent('dispatch', Array)
#16 /var/www/vendor/magento/module-store/App/FrontController/Plugin/RequestPreprocessor.php(99): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framewor
k\Interception\Interceptor::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#17 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\Store\App\FrontController\Plugin\RequestPreprocessor->aroundDispatch(Object(Magento\Framewor
k\App\FrontController\Interceptor), Object(Closure), Object(Magento\Framework\App\Request\Http))
#18 /var/www/vendor/magento/module-page-cache/Model/App/FrontController/BuiltinPlugin.php(72): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framework\
Interception\Interceptor::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#19 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\PageCache\Model\App\FrontController\BuiltinPlugin->aroundDispatch(Object(Magento\Framework\A
pp\FrontController\Interceptor), Object(Closure), Object(Magento\Framework\App\Request\Http))
#20 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Framework\App\FrontController\Interceptor->{closure:Magento\Framework\Interception\Intercept
or::___callPlugins():104}(Object(Magento\Framework\App\Request\Http))
#21 /var/www/generated/code/Magento/Framework/App/FrontController/Interceptor.php(23): Magento\Framework\App\FrontController\Interceptor->___callPlugins('dispatch', Array, N
ULL)
#22 /var/www/vendor/magento/framework/App/Http.php(116): Magento\Framework\App\FrontController\Interceptor->dispatch(Object(Magento\Framework\App\Request\Http))
#23 /var/www/vendor/magento/framework/Interception/Interceptor.php(58): Magento\Framework\App\Http->launch()
#24 /var/www/vendor/magento/framework/Interception/Interceptor.php(138): Magento\Framework\App\Http\Interceptor->___callParent('launch', Array)
#25 /var/www/vendor/magento/module-application-performance-monitor/Plugin/ApplicationPerformanceMonitor.php(38): Magento\Framework\App\Http\Interceptor->{closure:Magento\Fra
mework\Interception\Interceptor::___callPlugins():104}()
#26 /var/www/vendor/magento/framework/Interception/Interceptor.php(135): Magento\ApplicationPerformanceMonitor\Plugin\ApplicationPerformanceMonitor->aroundLaunch(Object(Mage
nto\Framework\App\Http\Interceptor), Object(Closure))
#27 /var/www/vendor/magento/framework/Interception/Interceptor.php(153): Magento\Framework\App\Http\Interceptor->{closure:Magento\Framework\Interception\Interceptor::___call
Plugins():104}()
#28 /var/www/generated/code/Magento/Framework/App/Http/Interceptor.php(23): Magento\Framework\App\Http\Interceptor->___callPlugins('launch', Array, NULL)
#29 /var/www/vendor/magento/framework/App/Bootstrap.php(264): Magento\Framework\App\Http\Interceptor->launch()
#30 /var/www/pub/index.php(30): Magento\Framework\App\Bootstrap->run(Object(Magento\Framework\App\Http\Interceptor))
#31 {main} {"report_id":"2ae3a657eaf9a9217bb256096f1da0896e4ce0d7afe08a8200685c8aa1283a3d","exception":"[object] (Exception(code: 0): Deprecated Functionality: Using null as
the key parameter for array_key_exists() is deprecated, use an empty string instead in /var/www/vendor/magento/module-captcha/Helper/Data.php on line 92 at /var/www/vendor/
magento/framework/App/ErrorHandler.php:61)"} []
<img width="1920" height="1080" alt="image" src="https://github.com/user-attachments/assets/500b817f-0a61-4f84-9d36-cf0f32b012c2" />Steps to reproduce
2. Go to Stores > Configuration > Sales > Checkout > Checkout Options and set Allow Guest Checkout to No, then flush the cache
3. Make sure CAPTCHA for the
user_login form is not forced (default config)4. As a not-logged-in customer, add a product to the cart and proceed to checkout — the "Checkout as a new customer / Checkout using your account" popup appears
5. In the "Checkout using your account" block, enter the credentials of an existing customer and click Sign In
6. Before the fix: the request fails with "Could not authenticate. Please try again later", and
var/report/var/log contains `report.CRITICAL: Exception: DeprecatedFunctionality: Using null as the key parameter for array_key_exists() ... in module-captcha/Helper/Data.php on line 92`
7. After the fix: the customer signs in successfully and no deprecation is logged
Taken from the upstream pull request.
Error signatures
- [2026-06-11T19:13:56.998006+00:00] report.CRITICAL: Exception: Deprecated Functionality: Using null as the key parameter for array_key_exists() is deprecated, use an empty s
- tring instead in
- [internal function]: Magento\Framework\App\ErrorHandler->handler(8192, 'Using null as t...', '', 92)
- {main} {"report_id":"","exception":"[object] (Exception(code: 0): Deprecated Functionality: Using null as
- magento/framework/App/ErrorHandler.php:61)"} []
- **Root cause:** when the AJAX login request payload does not contain `captcha_form_id`, `Magento\Captcha\Model\Customer\Plugin\AjaxLogin::aroundExecute()` resolves the form id to `null` and passes it
- 6. **Before the fix:** the request fails with "Could not authenticate. Please try again later", and `var/report`/`var/log` contains `report.CRITICAL: Exception: Deprecated
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: fails before, passes afterunit: fails before, passes after |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: fails before, passes afterunit: fails before, passes after |
| 2.4.9 | 2.4.9 clean | 2.4.9: fails before, passes afterunit: fails before, passes after |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 95.9%. Probability it is security relevant: 80.1%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 91.3%, refactor 3.2%, dependency 2.5%, tests_only 1.2%, feature 1.2%, docs_only 0.7% | 80.1% |
| Area | customer | customer 86.3%, checkout 7.6%, other 1.8% | 71.5% |
| Reported version | 2.4.9 | 2.4.9 30.8%, unspecified 10.8%, 2.4.8 2.2% | 10.1% |
| Scope | 0.77 of 2 | 1 57.7%, 0 32.5%, 2 9.8% | 17.2% |
| Risk | 0.87 of 2 | 0 49.0%, 2 36.4%, 1 14.5% | 9.1% |
| Worth backporting | 1.43 of 2 | 2 57.6%, 1 27.5%, 0 14.9% | 14.4% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40874/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-40874 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40874 Issue: https://github.com/magento/magento2/issues/40875 Author: @dimadidr Source commit: 0f74fbbef2f777ba8e61c8b211ded1aefb784db1 Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
