Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g897-jvjx-78vg

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

EPSS

Процентиль: 5%
0.00021
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

CVSS3: 5.3
nvd
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

CVSS3: 5.3
debian
около 1 месяца назад

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...

CVSS3: 5.3
redos
10 дней назад

Уязвимость curl

suse-cvrf
около 1 месяца назад

Security update for curl

EPSS

Процентиль: 5%
0.00021
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-601