VDB
CVE-2026-28875
CVE-2026-28875
PUBLISHED
CVSS 7.5 HIGH
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.
EPSS 0.14% · 34.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.14%
34.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | ipados | 0 |
| apple | iphone_os | 0 |
| Apple | iOS and iPadOS | 0 |
| curl | curl | 8.15.0, 8.14.1, 8.13.0 |
Exploit Intelligence
- http://www.openwall.com/lists/oss-security/2026/01/07/4 (circl)
- json (circl)
- www (circl)
- issue (circl)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
- CIRCL seen: CVE-2025-14524 (circl-sighting)
…and 177 more exploits
Timeline
- Oct 5, 2023 PoC Published
- Apr 28, 2025 PoC Published
- Oct 11, 2025 PoC Published
- Oct 12, 2025 PoC Published
- Oct 16, 2025 PoC Published
- Oct 17, 2025 PoC Published
- Oct 17, 2025 PoC Published
- Oct 21, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
- Oct 24, 2025 PoC Published
References
- https://support.apple.com/en-us/126793 advisory
- https://support.apple.com/en-us/126794 advisory
- https://support.apple.com/en-us/126798 advisory
- https://support.apple.com/en-us/126800 advisory
- https://support.apple.com/en-us/126796 advisory
- https://support.apple.com/en-us/126792 advisory
- https://support.apple.com/en-us/126795 advisory
- https://support.apple.com/en-us/126799 advisory
- https://support.apple.com/en-us/126797 advisory
- https://support.apple.com/en-us/126801 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28875 advisory
- json url
- www url
- issue url
- http://www.openwall.com/lists/oss-security/2026/01/07/4 url