CVE-2026-3783 is a vulnerability in haxx curl that can lead to the leakage of an OAuth2 bearer token. This occurs when an HTTP(S) transfer, using a bearer token, is redirected to a second hostname that has specific entries in the .netrc file, potentially exposing the token to the unintended host. Rated Medium (CVSS 5.3), the vulnerability has a network attack vector and low attack complexity, primarily impacting confidentiality by allowing unauthorized access to the token. While not currently listed on CISA KEV or having public exploit code, the vulnerability has garnered community attention and is being addressed through security updates by vendors like Ubuntu and SUSE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.33.0, <= 7.33.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.34.0, <= 7.34.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.35.0, <= 7.35.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.36.0, <= 7.36.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.37.0, <= 7.37.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.