When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass…
Medium CVSS 5.3
Summary
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://curl.se/docs/CVE-2025-14524.html Patch
- https://curl.se/docs/CVE-2025-14524.json Vendor Advisory
- https://hackerone.com/reports/3459417 Exploit
- http://www.openwall.com/lists/oss-security/2026/01/07/4 Mailing List
Timeline
- nvd_ingest NVD