CVE-2026-3783Patch(haxx / curl)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • General: 3 classified signals
  • Disclosure: 3 classified signals
  • Peaked 6d ago at 3 mentions (2026-03-11); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline13 mentions / 7d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-15: 2Mentions · 2026-03-18: 1Mentions · 2026-03-26: 2Mentions · 2026-07-13: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-26: 1Technical Details · 2026-07-13: 103-1103-1203-1303-1503-1803-2607-13
Signal classification4 categories
Patch
646.2%
General
323.1%
Disclosure
323.1%
Disclouser
17.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclouser1General1Patch1
2026-03-122
General1Patch1
2026-03-132
Patch2
2026-03-152
Disclosure2
2026-03-181
Patch1
2026-03-262
Disclosure1General1
2026-07-131
Patch1
Full discourse13 posts
  • H1 Disclosed - Public Disclosures@h1Disclosed
    General

    ⚡ Bearer Token Leaked to Attacker via .netrc Despite CVE-2026-3783 Fix 👨🏻‍💻 wizard021 ➟ curl ⬜ None 💰 None 🔗 https://hackerone.com/reports/3611825 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/vIQPYLUmVA

    Post summary

    A bug‑bounty report documents that bearer tokens can be leaked through the .netrc file even after CVE‑2026‑3783 was fixed, but no PoC, exploit code, or patch is provided.

    100133724
    10.1K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    4 Low to Medium CVEs fixed in curl https://www.openwall.com/lists/oss-security/2026/03/11/ CVE-2026-1965: bad reuse of HTTP Negotiate connection CVE-2026-3783: token leak with redirect and netrc CVE-2026-3784: wrong proxy connection reuse with credentials CVE-2026-3805: use after free in SMB connection reuse

    Post summary

    The post announces that four low‑to‑medium severity CVEs have been fixed in curl, giving brief technical details and linking to an OpenWall mailing list; no PoC, exploit, or active exploitation is mentioned.

    00063792
    4.4K followersView on X
  • H1 Disclosed - Public Disclosures@h1Disclosed
    Disclosure

    ⚡ CVE-2026-3783: token leak with redirect and netrc 👨🏻‍💻 spectreglobalsec ➟ curl 🟧 Medium 💰 None 🔗 https://hackerone.com/reports/3583983 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/XNZmhCU4Jz

    Post summary

    CVE-2026-3783 is a token leak vulnerability involving redirects and netrc, reported via a HackerOne link; the tweet provides technical details but no PoC, exploit code, or patch information.

    00071797
    10.1K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Bearer Token Leaked to Attacker via .netrc Despite CVE-2026-3783 Fix https://hackerone.com/reports/3611825 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The post states a bearer token leaked via .netrc despite the CVE‑2026‑3783 fix, but offers no PoC, exploit, patch details, or technical specifics.

    00002509
    40.3K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl モジュール更新情報 8.19.0-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 curl 8.19.0-1 この更新には脆弱性(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # ... https://kusanagi.tokyo/releases/23348/

    Post summary

    The kusanagi-curl module has been updated to 8.19.0‑1, providing patches for four CVE‑2026‑xxxx vulnerabilities, with no PoC, exploit code, or active exploitation details mentioned.

    01010150
    198 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3783 When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname un… https://www.cve.org/CVERecord?id=CVE-2026-3783

    Post summary

    CVE-2026-3783 reveals that curl may expose OAuth2 bearer tokens when following redirects, pointing to a disclosure of a token leakage vulnerability.

    00001148
    56.7K followersView on X
  • TECHEPAGES@techepages
    Patch

    9 curl CVEs patched in Debian 13.6 🚨 🔵 CVE-2026-3783/6253 – token & credential leaks on redirects 🔵 CVE-2026-3805/5773 – SMB UAF & wrong reuse 🔵 CVE-2026-1965/5545 – Negotiate auth bypass 🔵 CVE-2026-3784 – proxy auth bypass (CVSS 6.5) 🔵 CVE-2026-6276 – cookie leak 🔵 CVE-2026-4873 – TLS bypass apt upgrade ⬆️

    Post summary

    Debian 13.6 updates patch nine curl CVEs, covering token leaks, authentication bypasses, and a TLS bypass, with the post directing users to run ‘apt upgrade’.

    0000064
    19 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE & #openSUSE curl update fixes 4 CVEs! 🚨 Includes CVE-2026-1965 (HTTP Negotiate bypass), token leaks (CVE-2026-3783), and a critical SMB use-after-free (CVE-2026-3805). Read more: 👉 https://tinyurl.com/yc3p8esw #Security https://t.co/UrK4inqHTv

    Post summary

    The tweet announces a curl update that patches multiple CVEs, providing technical details but no exploit or active use information.

    0000046
    1.5K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl Module Update 8.19.0-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: curl 8.19.0-1 This update includes support for vulnerability(CVE-2026-3805, CVE-2026-3784, CVE-2026-3783, CVE-2026-1965). The module... https://kusanagi.tokyo/en/releases/23349/

    Post summary

    KUSANAGI released curl 8.19.0-1, patching CVE-2026-3805, CVE-2026-3784, CVE-2026-3783 and CVE-2026-1965.

    0000045
    198 followersView on X
  • DailyCVE@dailycve
    General

    🟠 cURL, Token Leak on Redirect, #CVE-2026-3783 (Medium) https://dailycve.com/curl-token-leak-on-redirect-cve-2026-3783-medium/

    Post summary

    The tweet references CVE-2026-3783—a token leak via redirect in cURL—without elaborating on exploitation, patches, or technical specifics.

    0000049
    167 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical curl vulnerabilities patched in #Ubuntu today. The update (USN-8084-1) addresses five CVEs, including a high-impact OAuth2 bearer token leak (CVE-2026-3783) and potential SMB heap overflow. Read more: 👉 https://tinyurl.com/bdhrsx9m #Security https://t.co/noQfTZpCJO

    Post summary

    Ubuntu released a critical update (USN-8084-1) to patch five curl-related CVEs, notably an OAuth2 bearer token leak (CVE-2026-3783) and a potential SMB heap overflow.

    0000044
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclouser

    CVE-2026-3783 OAuth2 Bearer Token Leakage in Curl via Unintended Redirect Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3783

    Post summary

    A brief CVE announcement highlighting an OAuth2 token leakage in cURL through unintended redirects; no further exploitation details, patches, or counter-claims are provided.

    0000017
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3783 - token leak with redirect and netrc Intel Report: https://ift.tt/NcmOGFQ

    Post summary

    The tweet references CVE-2026-3783 and notes a token leak involving redirects and netrc, but does not provide evidence of PoC, exploit code, active use, patch, or debunking. It is essentially a brief alert pointing to a report.

    0000028
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more