PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14524 curl CVE debrief

CVE-2025-14524 is a medium-severity vulnerability in the Haxx Curl product. When an OAuth2 bearer token is used for an HTTP(S) transfer and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, Curl might wrongly pass on the bearer token to the new target host. This issue requires verification of affected versions, exploitation, and remediation from official sources.

Vendor
curl
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-08
Original CVE updated
2026-09-15
Advisory published
2026-01-08
Advisory updated
2026-09-15

Who should care

Defenders responsible for Curl deployments, especially those using OAuth2 bearer tokens for authentication, should assess their exposure and verify if their configurations are vulnerable to this issue.

Why it matters

CVE-2025-14524 is a medium-severity vulnerability in Haxx Curl that might allow OAuth2 bearer tokens to be passed to unintended hosts during cross-protocol redirects. Defenders should verify exposure in their Curl deployments, especially where OAuth2 bearer tokens are used, and prioritize updates or patches from Haxx.

  • Potential unauthorized disclosure of OAuth2 bearer tokens
  • Possible misuse of tokens for unauthorized access
  • Need for verification of affected Curl versions and configurations
  • Priority on updating or patching vulnerable Curl deployments

Technical summary

The Haxx Curl product is vulnerable to a medium-severity issue (CVSS Score: 5.3) where an OAuth2 bearer token might be wrongly passed to a new target host during a cross-protocol redirect. This occurs when using an OAuth2 bearer token for an HTTP(S) transfer that redirects to a URL using IMAP, LDAP, POP3, or SMTP schemes. The issue requires verification of affected versions and configurations. Defenders should assess their exposure, especially where OAuth2 bearer tokens are used for authentication, and prioritize updates or patches from Haxx.

Defensive priority

Defenders should prioritize verifying exposure in their Curl deployments, especially where OAuth2 bearer tokens are used for authentication.

Recommended defensive actions

  • Verify Curl version and configuration for potential exposure
  • Review OAuth2 bearer token usage in Curl deployments
  • Monitor for updates from Haxx regarding CVE-2025-14524 remediation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but evidence of exploitation or specific affected versions is limited. Defenders should verify Curl versions, review configurations for potential exposure, and monitor for updates from Haxx regarding CVE-2025-14524 remediation. Evidence from official sources is crucial for accurate assessment and remediation planning.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14524 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14524

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14524 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14524

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://curl.se/docs/CVE-2025-14524.html

    2499f714-1537-4658-8207-48ae4bb9eae9 - Patch, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://curl.se/docs/CVE-2025-14524.json

    2499f714-1537-4658-8207-48ae4bb9eae9 - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3459417

    2499f714-1537-4658-8207-48ae4bb9eae9 - Exploit, Issue Tracking, Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.