CVE-2022-32206Allocation of Resources Without Limits or Throttling in Curl

Severity
6.5MEDIUMNVD
OSV4.3
EPSS
4.5%
top 10.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7
Latest updateSep 29

Description

curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages11 packages

CVEListV5https/github.com_curl_curlFixed in 7.84.0
NVDhaxx/curl< 7.84.0
Debianhaxx/curl< 7.74.0-1.3+deb11u2+3
Ubuntuhaxx/curl< 7.58.0-2ubuntu3.19+2
NVDsplunk/universal_forwarder8.2.08.2.12+2

Also affects: Debian Linux 10.0, 11.0, Fedora 35

Patches

🔴Vulnerability Details

5
OSV
curl regression2025-09-29
GHSA
GHSA-pphv-gw4r-gww8: curl < 72022-07-08
OSV
CVE-2022-32206: curl < 72022-07-07
CVEList
CVE-2022-32206: curl < 72022-07-07
OSV
curl vulnerabilities2022-06-27

📋Vendor Advisories

6
Apple
CVE-2022-32206: macOS Ventura 132022-10-24
Oracle
Oracle Oracle Communications Risk Matrix: Oracle Linux (cURL) — CVE-2022-322062022-10-15
Microsoft
curl < 7.84.0 supports "chained" HTTP compression algorithms meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" 2022-07-12
Ubuntu
curl vulnerabilities2022-06-27
Red Hat
curl: HTTP compression denial of service2022-06-27

💬Community

2
HackerOne
CVE-2022-32206: HTTP compression denial of service2022-06-27
HackerOne
CVE-2022-32206: HTTP compression denial of service2022-06-27
CVE-2022-32206 — Haxx Curl vulnerability | cvebase