CVE-2024-11053: Haxx Curl

Low severity, CVSS 3.4. EPSS: 1.3% chance of exploitation in the next 30 days.

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.

Affected products

  • Haxx Curl: from 7.76.0, before 8.11.1 (fixed in 8.11.1)
  • Netapp Bootstrap OS: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h610c Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp h615c Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Ontap: version 9 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2024-12-11. Last modified 2026-06-17.