Sploitus

CVE-2025-14524

No indexed exploits for CVE-2025-14524 yet

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.

Haxx Curl
< 8.18.0
CVSS 3.1
5.3 MEDIUM
EPSS
0.6% (46th percentile)
Weakness
CWE-601
NVD status
Analyzed
Published
2026-01-08
CVE-2025-14524 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-14524 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-14524 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.