Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-14524
curl curl — bearer token leak on cross-protocol redirect
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N R U H N N 5.3 .0066 50.0 —
AFFECTED
Product Versions Fixed
curl 7.33.0 – —
curl 06c1bea72faabb6fad4b7ef818aafaa336c9a7aa – —
curl 8.17.0 – —
TIMELINE
Dec 11 Reserved by curl
Jan 8 Published (CNA: curl)
Sep 15 EXPLOIT PUBLISHED — CVE-2025-14524 (curl). Public exploit reference added.
Description
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP,
POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new
target host.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| December 11, 2025 | Reserved | Reserved by curl |
| January 8, 2026 | Published | Published (CNA: curl) |
| September 15, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-14524 (curl). Public exploit reference added. |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| curl | curl | — | 7.33.0 | — |
| curl | curl | — | 06c1bea72faabb6fad4b7ef818aafaa336c9a7aa | — |
| curl | curl | — | 8.17.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-14524 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.