CVE-2021-22876 Details
Description
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| haxx libcurl | >= 7.1.1, <= 7.75.0 |
CPE
Remediation
| |
| fedoraproject fedora | 32 33 34 |
CPE
Remediation
| |
| netapp hci management node | All versions |
CPE
Remediation
| |
| netapp solidfire | All versions |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp hci storage node | All versions |
CPE
Remediation
| |
| broadcom fabric operating system | All versions |
CPE
Remediation
| |
| debian debian linux | 9.0 |
CPE
Remediation
| |
| siemens sinec infrastructure network services | < 1.0.1.1 |
CPE
Remediation
| |
| oracle communications billing and revenue management | 12.0.0.3.0 |
CPE
Remediation
| |
| oracle essbase | 21.2 |
CPE
Remediation
| |
| splunk universal forwarder | >= 8.2.0, < 8.2.12 >= 9.0.0, < 9.0.6 9.1.0 |
CPE
Remediation
| |
Change History
19 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 9, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 27, 2024 | Modified Analysis | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 6, 2022 | Modified Analysis | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jun 15, 2021 | Reanalysis | [email protected] |
| May 27, 2021 | Modified Analysis | [email protected] |
| May 26, 2021 | CVE Modified | [email protected] |
| May 21, 2021 | CVE Modified | [email protected] |
| May 17, 2021 | CVE Modified | [email protected] |
| Apr 22, 2021 | CVE Modified | [email protected] |
| Apr 6, 2021 | Initial Analysis | [email protected] |
| Apr 6, 2021 | CVE Modified | [email protected] |
| Apr 4, 2021 | CVE Modified | [email protected] |