Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2026-3783

CVE-2026-3783 : sévérité medium (CVSS 5.3). Aucune app du catalogue suivi n'est liée à cette CVE.

Gravité (CVSS)
5.3

Échelle NVD

Exploitation
0.5 %

EPSS, prédiction à 30 jours

Apps suivies
0
Encore exposées
0

EN When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a redirect to a second URL, curl could leak that token to the second
hostname under some circumstances.

If the hostname that the first request is redirected to has information in the
used .netrc file, with either of the `machine` or `default` keywords, curl
would pass on the bearer token set for the first host also to the second one.

Vecteur d'attaque : Réseau Aucun privilège requis Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS 0.45% exploit très peu probable percentile 38.7%

Versions d'OS qui corrigent cette CVE

Cette CVE est corrigée par les releases de sécurité OS suivantes. Mettre l'OS à jour au moins vers la version indiquée.

Voir sur NVD ↗ Advisory · curl.se