cbcvebase.
CVE-2022-32206
published 2022-07-07

CVE-2022-32206: curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different…

PriorityP345medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
31.97%
98.1th percentile
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos_ventura
debiancurl< curl 7.84.0-1 (bookworm)curl 7.84.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
haxxcurl< 7.84.07.84.0
haxxcurl>= 0 < 7.74.0-1.3+deb11u27.74.0-1.3+deb11u2
haxxcurl>= 0 < 7.84.0-17.84.0-1
haxxcurl>= 0 < 7.84.0-17.84.0-1
haxxcurl>= 0 < 7.84.0-17.84.0-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.197.58.0-2ubuntu3.19
haxxcurl>= 0 < 7.68.0-1ubuntu2.127.68.0-1ubuntu2.12
haxxcurl>= 0 < 7.81.0-1ubuntu1.37.81.0-1ubuntu1.3
haxxcurl>= 0 < 7.81.0-1ubuntu1.217.81.0-1ubuntu1.21
httpsgithub.com_curl_curl
msrcazl3_rust_1.75.0-14_on_azure_linux_3.0
msrcazl3_rust_1.86.0-1_on_azure_linux_3.0
msrccbl2_curl_7.84.0-1_on_cbl_mariner_2.0
msrccm1_curl_7.84.0-1_on_cbl_mariner_1.0
nodejsundici>= 0 < 6.23.06.23.0
nodejsundici>= 7.0.0 < 7.18.27.18.2
siemensscalance_sc622-2c_firmware< 3.03.0
siemensscalance_sc626-2c_firmware< 3.03.0
siemensscalance_sc632-2c_firmware< 3.03.0
siemensscalance_sc636-2c_firmware< 3.03.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.