VDB
CVE-2026-28862
CVE-2026-28862
PUBLISHED
CVSS 5.300000190734863 MEDIUM
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.
EPSS 0.06% · 18.9th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.06%
18.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | macOS | 0, 0, 0 |
| curl | curl | 7.70.0, 8.3.0, 8.5.0 |
| apple | macos | 14.0, 26.0, 15.0 |
Exploit Intelligence
- http://www.openwall.com/lists/oss-security/2026/01/07/4 (circl)
- json (circl)
- www (circl)
- issue (circl)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
…and 181 more exploits
Timeline
- Oct 5, 2023 PoC Published
- Apr 28, 2025 PoC Published
- Oct 11, 2025 PoC Published
- Oct 12, 2025 PoC Published
- Oct 16, 2025 PoC Published
- Oct 17, 2025 PoC Published
- Oct 17, 2025 PoC Published
- Oct 21, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
References
- https://support.apple.com/en-us/126793 advisory
- https://support.apple.com/en-us/126794 advisory
- https://support.apple.com/en-us/126798 advisory
- https://support.apple.com/en-us/126800 advisory
- https://support.apple.com/en-us/126796 advisory
- https://support.apple.com/en-us/126792 advisory
- https://support.apple.com/en-us/126795 advisory
- https://support.apple.com/en-us/126799 advisory
- https://support.apple.com/en-us/126797 advisory
- https://support.apple.com/en-us/126801 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28862 advisory
- json url
- www url
- issue url
- http://www.openwall.com/lists/oss-security/2026/01/07/4 url