curl vulnerability

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

Published 8 Jan 2026Updated 15 Sep 20266 sources
CVSS 5.3 ✓ VERIFIED REFERENCE

What happened

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

Affected versions

curl: 7.33.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); 06c1bea72faabb6fad4b7ef818aafaa336c9a7aa through before 1a822275d333dc6da6043497160fd04c8fa48640 (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
hackerone.comNVD reference2026-01-08Verified