Description
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3288-1 | curl security update |
Debian DSA |
DSA-5197-1 | curl security update |
Debian DSA |
DSA-5330-1 | curl security update |
Debian DSA |
DSA-5365-1 | curl security update |
Ubuntu USN |
USN-5397-1 | curl vulnerabilities |
References
History
Thu, 16 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Brocade
Subscribe
Fabric Operating System
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Haxx
Subscribe
Curl
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Hci Bootstrap Os
Subscribe
Hci Compute Node
Subscribe
Solidfire \& Hci Management Node
Subscribe
Solidfire \& Hci Storage Node
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Splunk
Subscribe
Universal Forwarder
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-04-16T13:41:41.899Z
Reserved: 2022-03-23T00:00:00.000Z
Link: CVE-2022-27774
Updated: 2024-08-03T05:32:59.946Z
Status : Modified
Published: 2022-06-02T14:15:43.317
Modified: 2026-04-16T14:16:11.973
Link: CVE-2022-27774
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN