PatchSiren cyber security CVE debrief
CVE-2025-14524 curl CVE debrief
CVE-2025-14524 is a medium-severity vulnerability in the Haxx Curl product. When an OAuth2 bearer token is used for an HTTP(S) transfer and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, Curl might wrongly pass on the bearer token to the new target host. This issue requires verification of affected versions, exploitation, and remediation from official sources.
- Vendor
- curl
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-08
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-01-08
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for Curl deployments, especially those using OAuth2 bearer tokens for authentication, should assess their exposure and verify if their configurations are vulnerable to this issue.
Why it matters
CVE-2025-14524 is a medium-severity vulnerability in Haxx Curl that might allow OAuth2 bearer tokens to be passed to unintended hosts during cross-protocol redirects. Defenders should verify exposure in their Curl deployments, especially where OAuth2 bearer tokens are used, and prioritize updates or patches from Haxx.
- Potential unauthorized disclosure of OAuth2 bearer tokens
- Possible misuse of tokens for unauthorized access
- Need for verification of affected Curl versions and configurations
- Priority on updating or patching vulnerable Curl deployments
Technical summary
The Haxx Curl product is vulnerable to a medium-severity issue (CVSS Score: 5.3) where an OAuth2 bearer token might be wrongly passed to a new target host during a cross-protocol redirect. This occurs when using an OAuth2 bearer token for an HTTP(S) transfer that redirects to a URL using IMAP, LDAP, POP3, or SMTP schemes. The issue requires verification of affected versions and configurations. Defenders should assess their exposure, especially where OAuth2 bearer tokens are used for authentication, and prioritize updates or patches from Haxx.
Defensive priority
Defenders should prioritize verifying exposure in their Curl deployments, especially where OAuth2 bearer tokens are used for authentication.
Recommended defensive actions
- Verify Curl version and configuration for potential exposure
- Review OAuth2 bearer token usage in Curl deployments
- Monitor for updates from Haxx regarding CVE-2025-14524 remediation
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but evidence of exploitation or specific affected versions is limited. Defenders should verify Curl versions, review configurations for potential exposure, and monitor for updates from Haxx regarding CVE-2025-14524 remediation. Evidence from official sources is crucial for accurate assessment and remediation planning.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14524 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14524
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14524 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14524
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://curl.se/docs/CVE-2025-14524.html
2499f714-1537-4658-8207-48ae4bb9eae9 - Patch, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://curl.se/docs/CVE-2025-14524.json
2499f714-1537-4658-8207-48ae4bb9eae9 - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://hackerone.com/reports/3459417
2499f714-1537-4658-8207-48ae4bb9eae9 - Exploit, Issue Tracking, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.