PT-2024-9413 · Curl+13 · Curl+13

Daniel Stenberg

+1

·

Published

2024-11-08

·

Updated

2026-05-18

·

CVE-2024-11053

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: curl versions 6.5 through 8.11.0
Description: The issue arises when curl is used with a .netrc file for credentials and follows HTTP redirects. Under certain circumstances, curl could leak the password used for the first host to the followed-to host. This flaw only manifests itself if the .netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
Recommendations: For versions 6.5 through 8.11.0, upgrade to version 8.11.1 or later to mitigate the risk of credential leakage. As a temporary workaround, consider avoiding the use of .netrc files with curl or restricting access to sensitive information when following HTTP redirects.

Exploit

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:1671
ALSA-2025:1673
ALT-PU-2024-16919
ALT-PU-2024-17124
ALT-PU-2024-17523
ALT-PU-2025-1416
AZL-54147
AZL-54155
AZL-54212
AZL-54219
AZL-54221
AZL-54233
AZL-54240
BDU:2024-11106
CESA-2025_1673
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2024-11053
INFSA-2025_1671
INFSA-2025_1673
JLSEC-2026-413
MGASA-2024-0391
OESA-2025-1021
OESA-2025-1022
OESA-2025-1023
OESA-2025-1024
OESA-2025-1025
OPENSUSE-SU-2024:14575-1
OPENSUSE-SU-2024_4288-1
OPENSUSE-SU-2024_4359-1
RHSA-2025:1671
RHSA-2025:1673
RHSA-2025_1671
RHSA-2025_1673
RLSA-2025:1671
RLSA-2025:1673
SUSE-SU-2024:4284-1
SUSE-SU-2024:4284-2
SUSE-SU-2024:4287-1
SUSE-SU-2024:4288-1
SUSE-SU-2024:4359-1
SUSE-SU-2024_4284-1
SUSE-SU-2024_4284-2
SUSE-SU-2024_4288-1
SUSE-SU-2024_4359-1
SUSE-SU-2025:20106-1
SUSE-SU-2025:20239-1
USN-7162-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Ibm Aix
Linuxmint
Mysql Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Curl