VDB
GCVE-110-NCSC-2026-319
GCVE-110-NCSC-2026-319
Advisory PublishedCVSS 5.4/10
A curl vulnerability in versions 7.33.0 to before 8.19.0 can leak OAuth2 bearer tokens to redirected hosts with .netrc entries, affecting products like NetApp and Apple software and risking unauthorized credential exposure.
Weaknesses (CWE)
CWE-522Insufficiently Protected CredentialsCWE-305Authentication Bypass by Primary WeaknessCWE-125Out-of-bounds ReadCWE-416Use After FreeCWE-190Integer Overflow or WraparoundCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-121Stack-based Buffer OverflowCWE-617Reachable AssertionCWE-346Origin Validation ErrorCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-352Cross-Site Request Forgery (CSRF)CWE-787Out-of-bounds WriteCWE-732Incorrect Permission Assignment for Critical ResourceCWE-451User Interface (UI) Misrepresentation of Critical InformationCWE-319Cleartext Transmission of Sensitive InformationCWE-862Missing Authorization
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apple | vers:unknown/* | — | — |
Aliases
CVE-2026-28947CVE-2026-28958CVE-2026-28973CVE-2026-28979CVE-2026-28984CVE-2026-28990CVE-2026-28996CVE-2026-3783CVE-2026-3784CVE-2026-39868CVE-2026-39872CVE-2026-39877CVE-2026-43658CVE-2026-43661CVE-2026-43663CVE-2026-43667CVE-2026-43673CVE-2026-43676CVE-2026-43699CVE-2026-43700CVE-2026-43701CVE-2026-43705CVE-2026-43708CVE-2026-43711CVE-2026-43714CVE-2026-43717CVE-2026-43720CVE-2026-43722CVE-2026-43723CVE-2026-43724CVE-2026-43725CVE-2026-43726CVE-2026-43727CVE-2026-43729CVE-2026-43731CVE-2026-43733CVE-2026-43734CVE-2026-43735CVE-2026-43738CVE-2026-43742CVE-2026-43744CVE-2026-43745CVE-2026-43754CVE-2026-43757CVE-2026-43769CVE-2026-43776CVE-2026-43778CVE-2026-43794CVE-2026-43795CVE-2026-43796CVE-2026-43797CVE-2026-43799CVE-2026-43800CVE-2026-43801CVE-2026-43802CVE-2026-43803CVE-2026-43807CVE-2026-43809CVE-2026-43810CVE-2026-43811CVE-2026-43812CVE-2026-43818CVE-2026-43821CVE-2026-43822CVE-2026-4424CVE-2026-64692CVE-2026-64693CVE-2026-64695CVE-2026-64700CVE-2026-64707CVE-2026-64709CVE-2026-64715CVE-2026-64716CVE-2026-64719CVE-2026-64721CVE-2026-64722CVE-2026-64723CVE-2026-64724CVE-2026-64725CVE-2026-64726CVE-2026-64732CVE-2026-64734CVE-2026-64735CVE-2026-64738CVE-2026-64739CVE-2026-64740CVE-2026-64742CVE-2026-64743CVE-2026-64744CVE-2026-64746CVE-2026-64747CVE-2026-64749CVE-2026-64755CVE-2026-64757CVE-2026-64760CVE-2026-64762CVE-2026-64763CVE-2026-64764CVE-2026-64765CVE-2026-64766CVE-2026-64768CVE-2026-64769CVE-2026-64770CVE-2026-64771CVE-2026-64772CVE-2026-64774CVE-2026-64778CVE-2026-64779CVE-2026-64780CVE-2026-64781CVE-2026-64782CVE-2026-64784CVE-2026-65331CVE-2026-65332CVE-2026-65333CVE-2026-65334CVE-2026-65335CVE-2026-65336CVE-2026-65337CVE-2026-65338CVE-2026-65340CVE-2026-65341
References
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.