THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3783 (MEDIUM 5.3) — When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .ne

[NVD] CVE-2026-3783 (MEDIUM 5.3) — When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .ne

lownvdPublished 2026-03-11

CVE-2026-3783 CVSS: 5.3 MEDIUM Published: 2026-03-11T11:16:00.080

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.

If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` k

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3783