TROYANOSYVIRUS
Retour aux CVEs

CVE-2026-3783

MEDIUM
5.3

Description

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.

Details CVE

Score CVSS v3.15.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/11/2026
Derniere modification3/12/2026
Sourcenvd
Observations honeypot0

Produits affectes

haxx:curl

Faiblesses (CWE)

CWE-522

References

https://curl.se/docs/CVE-2026-3783.html(2499f714-1537-4658-8207-48ae4bb9eae9)
https://curl.se/docs/CVE-2026-3783.json(2499f714-1537-4658-8207-48ae4bb9eae9)
https://hackerone.com/reports/3583983(2499f714-1537-4658-8207-48ae4bb9eae9)
http://www.openwall.com/lists/oss-security/2026/03/11/2(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.