Insufficiently protected credentials in cURL - CVE-2025-14524

 

Insufficiently protected credentials in cURL - CVE-2025-14524

Published: January 7, 2026


Vulnerability identifier: #VU121026
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-14524
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to obtain bearer token,

The vulnerability exists due to an error when handling cross-protocol redirects. When an oauth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.


Affected software

cURL
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
macOS
Ubuntu
Basesystem Module
openSUSE Leap
iPadOS
Apple iOS
openEuler
Anolis OS
tvOS
visionOS
watchOS
SecurityCenter
Nessus Network Monitor
LANTIME Operating System Firmware (LTOS)
curl (Ubuntu package)
curl-debugsource
curl-debuginfo
curl
libcurl
libcurl-devel
curl-help
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4
libcurl-minimal
curl-doc
curl-minimal
libcurl-devel-32bit
libcurl-devel-64bit
libcurl4-64bit
libcurl4-64bit-debuginfo
libcurl4-32bit-debuginfo
libcurl-devel-doc
curl-fish-completion
libcurl-mini4-debuginfo
libcurl-mini4
curl-mini-debugsource
curl-zsh-completion

How to mitigate CVE-2025-14524

Install updates from vendor's website.

cURL - update to 8.18.0
SecurityCenter - addressed in versions SC-202602.1, SC-202602.2
Nessus Network Monitor - update to 6.5.3
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
macOS - addressed in versions 14.8.5 23J423, 15.7.5 24G624, 26.4 25E246
iPadOS - addressed in versions 18.7.7 22H333, 26.4 23E246
Apple iOS - addressed in versions 18.7.7 22H333, 26.4 23E246
tvOS - update to 26.4 23L243
visionOS - update to 26.4
watchOS - update to 26.4 23T240
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm19, 7.47.0-1ubuntu2.19+esm15, 7.58.0-2ubuntu3.24+esm7, 7.68.0-1ubuntu2.25+esm2, 7.81.0-1ubuntu1.22, 8.5.0-2ubuntu10.7, 8.14.1-2ubuntu1.1
curl-debugsource - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
curl-debuginfo - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
curl - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
libcurl - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
libcurl-devel - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
curl-help - addressed in versions 7.71.1-45, 7.79.1-46, 8.4.0-26
curl - addressed in versions 8.0.1-11.111.1, 8.14.1-150200.4.97.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.111.1, 8.14.1-150200.4.97.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
curl-debugsource - addressed in versions 8.0.1-11.111.1, 8.14.1-150200.4.97.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
curl-debuginfo - addressed in versions 8.0.1-11.111.1, 8.14.1-150200.4.97.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl-devel - addressed in versions 8.0.1-11.111.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.111.1
libcurl4-32bit - addressed in versions 8.0.1-11.111.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl4 - addressed in versions 8.0.1-11.111.1, 8.14.1-150200.4.97.1, 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl - update to 8.4.0-13
libcurl-devel - update to 8.4.0-13
libcurl-minimal - update to 8.4.0-13
curl-doc - update to 8.4.0-13
curl-minimal - update to 8.4.0-13
curl - update to 8.4.0-13
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1, 8.14.1-150700.7.8.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.77.1, 8.14.1-150600.4.34.1

External References

Related Security Bulletins