REDHAT-BUG-2446450: Medium severity curl curl vulnerability

Published Mar 11, 2026
·
Updated

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.

If the hostname that the first request is redirected to has information in the used .netrc file, with either of the machine or default keywords, curl would pass on the bearer token set for the first host also to the second one.

Affected Software

1 affected component
curl curl

Event History

Mar 11, 2026
Data Sourced
via Red Hat·11:01 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What conditions are required for the bearer token to be sent to another host?

An HTTP(S) transfer using an OAuth2 bearer token must redirect to a second URL. The second hostname must have matching information in the .netrc file through either a machine entry or a default entry.

2

Are .netrc default entries relevant, or only per-host machine entries?

Both are relevant. The token can be passed to the redirected hostname when the .netrc file contains either a machine entry for that host or a default entry.

3

How can I assess whether a transfer may be affected?

Identify curl HTTP(S) transfers that use OAuth2 bearer tokens and follow redirects to a different hostname. Check whether the .netrc file used by those transfers contains a machine or default entry that applies to the redirected hostname.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203