PT-2021-4570 · Curl+9 · Curl+9

Viktor Szakats

·

Published

2021-02-12

·

Updated

2026-05-18

·

CVE-2021-22876

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl versions 7.1.1 through 7.75.0
Description The issue is related to the exposure of private personal information to an unauthorized actor by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. This can be exploited by a remote attacker to gain access to confidential data.
Recommendations For curl versions 7.1.1 through 7.75.0, consider disabling the automatic population of the Referer: HTTP request header field by not setting the CURLOPT AUTOREFERER option or by not using the --referer ";auto" option with the curl tool, until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4511
ALT-PU-2021-1581
ALT-PU-2021-1601
ALT-PU-2021-2146
BDU:2021-05241
CESA-2021_4511
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2021-22876
DLA-2664-1
DSA-4881-1
JLSEC-2025-26
MGASA-2021-0186
OESA-2021-1170
OPENSUSE-SU-2021:0510-1
OPENSUSE-SU-2021_0510-1
OPENSUSE-SU-2024:10582-1
RHSA-2021:2472
RHSA-2021:4511
RHSA-2021_4511
RHSA-2022:1354
RLSA-2021:4511
SUSE-SU-2021:1006-1
SUSE-SU-2021:1396-1
SUSE-SU-2021:14707-1
SUSE-SU-2021:1786-1
SUSE-SU-2021:1809-1
SUSE-SU-2021_1006-1
SUSE-SU-2021_1396-1
SUSE-SU-2021_14707-1
USN-4898-1
USN-4903-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Curl