THREAT OPS › Threat News › [NVD] CVE-2026-3783 (MEDIUM 5.3) — When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a redirect to a second URL, curl could leak that token to the second
hostname under some circumstances.
If the hostname that the first request is redirected to has information in the
used .ne
[NVD] CVE-2026-3783 (MEDIUM 5.3) — When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .ne
CVE-2026-3783 CVSS: 5.3 MEDIUM Published: 2026-03-11T11:16:00.080
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.
If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` k
Indicators of compromise
- CVE-2026-3783cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3783