CVE Vulnerabilities

CVE-2026-3783

Insufficiently Protected Credentials

Published: Mar 11, 2026 | Modified: Sep 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.7 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.

If the hostname that the first request is redirected to has information in the used .netrc file, with either of the machine or default keywords, curl would pass on the bearer token set for the first host also to the second one.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.33.0 (including)8.19.0 (excluding)
Red Hat Enterprise Linux 10RedHatcurl-0:8.12.1-4.el10_2.3*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-40.el9_8.5*
Red Hat Enterprise Linux 9RedHatcurl-0:7.76.1-40.el9_8.5*
Cert Manager support for Red Hat OpenShift release 1.19RedHatcert-manager/cert-manager-operator-rhel9:1788348522*
Cert Manager support for Red Hat OpenShift release 1.19RedHatcert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571*
Cert Manager support for Red Hat OpenShift release 1.19RedHatcert-manager/jetstack-cert-manager-rhel9:1788348571*
Cert Manager support for Red Hat OpenShift release 1.19RedHatcert-manager/cert-manager-istio-csr-rhel9:1788348594*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1788205779*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1788206196*
Red Hat Hardened ImagesRedHatcurl-main-8.19.0-3.hum1*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-tp-rhel9:1787241211*
Red Hat Update Infrastructure 5RedHatrhui5/installer-tp-rhel9:1787135742*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-tp-rhel9:1787241260*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-rhel9:1788880445*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1788880464*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1788880456*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1788765051*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1788880581*
CurlUbuntudevel*
CurlUbuntuesm-infra/focal*
CurlUbuntujammy*
CurlUbuntunoble*
CurlUbuntuquesting*
CurlUbunturesolute*
CurlUbuntuupstream*

Potential Mitigations

References