https://seclists.org/oss-sec/2026/q1/33: [ADVISORY] curl CVE-2025-14524: bear token leak on cross-protocol dict
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
redhat/curl>=7.33.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-14524?
CVE-2025-14524 has been classified with a critical severity due to the potential exposure of sensitive bearer tokens.
2
How do I fix CVE-2025-14524?
To address CVE-2025-14524, update your curl software to the latest version that has implemented the necessary patches.
3
What type of systems are affected by CVE-2025-14524?
CVE-2025-14524 affects systems using curl with OAuth2 bearer tokens during cross-protocol redirects.
4
Does CVE-2025-14524 affect other libraries apart from curl?
CVE-2025-14524 is specifically related to the curl library and does not indicate similar vulnerabilities in other libraries.
5
What is the potential impact of CVE-2025-14524 if exploited?
If exploited, CVE-2025-14524 can lead to unauthorized access to resources, as sensitive bearer tokens may be leaked to unintended parties.