Loading HuntDB...

GHSA-jjr6-2g8j-hmwr

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

Related CVEs

Key Information

GHSA ID
GHSA-jjr6-2g8j-hmwr
Published
May 24, 2022 5:46 PM
Last Modified
March 27, 2024 6:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.