Junglewise Threat Intelligence

CVE-2025-14524: curl bearer token leak on cross-protocol redirect

CVE-2025-14524 · Severity: medium · CVSS 5.3 · Published 2026-01-08

Technologies: Curl. Vendors: Haxx.

Executive brief

curl is a widely-used library and command-line tool for transferring data using URLs. When curl follows an HTTP redirect to an alternative protocol (IMAP, LDAP, POP3, or SMTP), it may incorrectly send OAuth2 bearer tokens to the new destination, leaking authentication credentials to an attacker-controlled server. This affects applications that use OAuth2 authentication and allow protocol-switching redirects.

Technical details

This is a credential exposure vulnerability (CWE-522) in curl's redirect handling. When an application uses OAuth2 bearer tokens for HTTP(S) requests and enables redirects to non-HTTP protocols (IMAP, LDAP, POP3, SMTP), curl incorrectly forwards the bearer token to the new target if the redirect URL contains a username component. The vulnerability requires specific preconditions: OAuth2 bearer token usage, explicit enablement of cross-protocol redirects (disabled by default), and a redirect URL with a username field. An attacker can exploit this by creating a malicious HTTP response with a redirect header pointing to a controlled server using an alternative protocol, causing the victim's OAuth2 token to be transmitted in plaintext to the attacker. The flaw was fixed in curl 8.18.0 (released January 7, 2026) and in maintenance releases 8.16.1 and 8.14.2.

Affected products

  • curl curl 7.33.0 to 8.17.0 (except 8.14.2, 8.16.1, 8.18.0+)

Timeline

  • 2025-12-09: disclosed: Vulnerability reported to curl project
  • 2026-01-07: advisory: Security advisory published
  • 2026-01-07: patched: curl 8.18.0 released with fix

References

Related threats