CVE-2025-14524

Published: January 9, 2026Last modified: January 15, 2026

Description

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita LinuxStreamcurlFixed (8.18.0-r0)
Hardened ContainersStreamcurlFixed (8.18.0-r0)

References

ON THIS PAGE