When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP,
POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new
target host.
CVSS
No CVSS.
References
Configurations
No configuration.
History
08 Jan 2026, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Jan 2026, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-08 10:15
Updated : 2026-01-08 18:08
NVD link : CVE-2025-14524
Mitre link : CVE-2025-14524
CVE.ORG link : CVE-2025-14524
JSON object : View
Products Affected
No product.
CWE
No CWE.
