CVE-2025-14524

Source
https://cve.org/CVERecord?id=CVE-2025-14524
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-14524.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-14524
Aliases
Downstream
Related
Published
2026-01-08T10:07:25.655Z
Modified
2026-05-18T05:59:11.433088865Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
bearer token leak on cross-protocol redirect
Details

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

Database specific
{
    "cna_assigner": "curl",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14524.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "8.17.0"
                },
                {
                    "last_affected": "8.16.0"
                },
                {
                    "last_affected": "8.15.0"
                },
                {
                    "last_affected": "8.14.1"
                },
                {
                    "last_affected": "8.14.0"
                },
                {
                    "last_affected": "8.13.0"
                },
                {
                    "last_affected": "8.12.1"
                },
                {
                    "last_affected": "8.12.0"
                },
                {
                    "last_affected": "8.11.1"
                },
                {
                    "last_affected": "8.11.0"
                },
                {
                    "last_affected": "8.10.1"
                },
                {
                    "last_affected": "8.10.0"
                },
                {
                    "last_affected": "8.9.1"
                },
                {
                    "last_affected": "8.9.0"
                },
                {
                    "last_affected": "8.8.0"
                },
                {
                    "last_affected": "8.7.1"
                },
                {
                    "last_affected": "8.7.0"
                },
                {
                    "last_affected": "8.6.0"
                },
                {
                    "last_affected": "8.5.0"
                },
                {
                    "last_affected": "8.4.0"
                },
                {
                    "last_affected": "8.3.0"
                },
                {
                    "last_affected": "8.2.1"
                },
                {
                    "last_affected": "8.2.0"
                },
                {
                    "last_affected": "8.1.2"
                },
                {
                    "last_affected": "8.1.1"
                },
                {
                    "last_affected": "8.1.0"
                },
                {
                    "last_affected": "8.0.1"
                },
                {
                    "last_affected": "8.0.0"
                },
                {
                    "last_affected": "7.88.1"
                },
                {
                    "last_affected": "7.88.0"
                },
                {
                    "last_affected": "7.87.0"
                },
                {
                    "last_affected": "7.86.0"
                },
                {
                    "last_affected": "7.85.0"
                },
                {
                    "last_affected": "7.84.0"
                },
                {
                    "last_affected": "7.83.1"
                },
                {
                    "last_affected": "7.83.0"
                },
                {
                    "last_affected": "7.82.0"
                },
                {
                    "last_affected": "7.81.0"
                },
                {
                    "last_affected": "7.80.0"
                },
                {
                    "last_affected": "7.79.1"
                },
                {
                    "last_affected": "7.79.0"
                },
                {
                    "last_affected": "7.78.0"
                },
                {
                    "last_affected": "7.77.0"
                },
                {
                    "last_affected": "7.76.1"
                },
                {
                    "last_affected": "7.76.0"
                },
                {
                    "last_affected": "7.75.0"
                },
                {
                    "last_affected": "7.74.0"
                },
                {
                    "last_affected": "7.73.0"
                },
                {
                    "last_affected": "7.72.0"
                },
                {
                    "last_affected": "7.71.1"
                },
                {
                    "last_affected": "7.71.0"
                },
                {
                    "last_affected": "7.70.0"
                },
                {
                    "last_affected": "7.69.1"
                },
                {
                    "last_affected": "7.69.0"
                },
                {
                    "last_affected": "7.68.0"
                },
                {
                    "last_affected": "7.67.0"
                },
                {
                    "last_affected": "7.66.0"
                },
                {
                    "last_affected": "7.65.3"
                },
                {
                    "last_affected": "7.65.2"
                },
                {
                    "last_affected": "7.65.1"
                },
                {
                    "last_affected": "7.65.0"
                },
                {
                    "last_affected": "7.64.1"
                },
                {
                    "last_affected": "7.64.0"
                },
                {
                    "last_affected": "7.63.0"
                },
                {
                    "last_affected": "7.62.0"
                },
                {
                    "last_affected": "7.61.1"
                },
                {
                    "last_affected": "7.61.0"
                },
                {
                    "last_affected": "7.60.0"
                },
                {
                    "last_affected": "7.59.0"
                },
                {
                    "last_affected": "7.58.0"
                },
                {
                    "last_affected": "7.57.0"
                },
                {
                    "last_affected": "7.56.1"
                },
                {
                    "last_affected": "7.56.0"
                },
                {
                    "last_affected": "7.55.1"
                },
                {
                    "last_affected": "7.55.0"
                },
                {
                    "last_affected": "7.54.1"
                },
                {
                    "last_affected": "7.54.0"
                },
                {
                    "last_affected": "7.53.1"
                },
                {
                    "last_affected": "7.53.0"
                },
                {
                    "last_affected": "7.52.1"
                },
                {
                    "last_affected": "7.52.0"
                },
                {
                    "last_affected": "7.51.0"
                },
                {
                    "last_affected": "7.50.3"
                },
                {
                    "last_affected": "7.50.2"
                },
                {
                    "last_affected": "7.50.1"
                },
                {
                    "last_affected": "7.50.0"
                },
                {
                    "last_affected": "7.49.1"
                },
                {
                    "last_affected": "7.49.0"
                },
                {
                    "last_affected": "7.48.0"
                },
                {
                    "last_affected": "7.47.1"
                },
                {
                    "last_affected": "7.47.0"
                },
                {
                    "last_affected": "7.46.0"
                },
                {
                    "last_affected": "7.45.0"
                },
                {
                    "last_affected": "7.44.0"
                },
                {
                    "last_affected": "7.43.0"
                },
                {
                    "last_affected": "7.42.1"
                },
                {
                    "last_affected": "7.42.0"
                },
                {
                    "last_affected": "7.41.0"
                },
                {
                    "last_affected": "7.40.0"
                },
                {
                    "last_affected": "7.39.0"
                },
                {
                    "last_affected": "7.38.0"
                },
                {
                    "last_affected": "7.37.1"
                },
                {
                    "last_affected": "7.37.0"
                },
                {
                    "last_affected": "7.36.0"
                },
                {
                    "last_affected": "7.35.0"
                },
                {
                    "last_affected": "7.34.0"
                },
                {
                    "last_affected": "7.33.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/curl/curl

Affected ranges

Type
GIT
Repo
https://github.com/curl/curl
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "7.33.0"
        },
        {
            "fixed": "8.18.0"
        }
    ],
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"
}

Affected versions

Other
curl-7_33_0
curl-7_34_0
curl-7_35_0
curl-7_36_0
curl-7_37_0
curl-7_37_1
curl-7_38_0
curl-7_39_0
curl-7_40_0
curl-7_41_0
curl-7_42_0
curl-7_43_0
curl-7_44_0
curl-7_45_0
curl-7_46_0
curl-7_47_0
curl-7_47_1
curl-7_48_0
curl-7_49_0
curl-7_49_1
curl-7_50_0
curl-7_50_1
curl-7_50_2
curl-7_50_3
curl-7_51_0
curl-7_52_0
curl-7_52_1
curl-7_53_0
curl-7_53_1
curl-7_54_0
curl-7_54_1
curl-7_55_0
curl-7_55_1
curl-7_56_0
curl-7_56_1
curl-7_57_0
curl-7_58_0
curl-7_59_0
curl-7_60_0
curl-7_61_0
curl-7_61_1
curl-7_62_0
curl-7_63_0
curl-7_64_0
curl-7_64_1
curl-7_65_0
curl-7_65_1
curl-7_65_2
curl-7_65_3
curl-7_66_0
curl-7_67_0
curl-7_68_0
curl-7_69_0
curl-7_69_1
curl-7_70_0
curl-7_71_0
curl-7_71_1
curl-7_72_0
curl-7_73_0
curl-7_74_0
curl-7_75_0
curl-7_76_0
curl-7_76_1
curl-7_77_0
curl-7_78_0
curl-7_79_0
curl-7_79_1
curl-7_80_0
curl-7_81_0
curl-7_82_0
curl-7_83_0
curl-7_83_1
curl-7_84_0
curl-7_85_0
curl-7_86_0
curl-7_87_0
curl-7_88_0
curl-7_88_1
curl-8_0_0
curl-8_0_1
curl-8_10_0
curl-8_10_1
curl-8_11_0
curl-8_11_1
curl-8_12_0
curl-8_12_1
curl-8_13_0
curl-8_14_0
curl-8_14_1
curl-8_15_0
curl-8_16_0
curl-8_17_0
curl-8_1_0
curl-8_1_1
curl-8_1_2
curl-8_2_0
curl-8_2_1
curl-8_3_0
curl-8_4_0
curl-8_5_0
curl-8_6_0
curl-8_7_0
curl-8_7_1
curl-8_8_0
curl-8_9_0
curl-8_9_1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-14524.json"