Skip to main content

CVE-2026-3783

CVE Details

Visit the official vulnerability details page for CVE-2026-3783 to learn more.

Initial Publication

03/11/2026

Last Update

03/12/2026

Third Party Dependency

curl

NIST CVE Summary

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.

If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one.

CVE Severity

5.3

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.0-rc.1⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.