Haxx Curl vulnerabilities
217 known vulnerabilities affecting haxx/curl.
Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14
Vulnerabilities
Page 10 of 11
CVE-2017-9502P4MEDIUMCVSS 5.3≤ 7.54.02017-06-14
CVE-2017-9502 [MEDIUM] CWE-119 CVE-2017-9502: In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic th
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FIL
nvd
CVE-2016-0754P4MEDIUMCVSS 5.3≤ 7.46.02016-01-29
CVE-2016-0754 [MEDIUM] CWE-20 CVE-2016-0754: cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working di
cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name.
nvd
CVE-2025-14819P4MEDIUMCVSS 5.3≥ 7.87.0, < 8.18.02026-01-08
CVE-2025-14819 [MEDIUM] CWE-295 CVE-2025-14819: When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_P
When doing TLS related transfers with reused easy or multi handles and
altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally
reuse a CA store cached in memory for which the partial chain option was
reversed. Contrary to the user's wishes and expectations. This could make
libcurl find and accept a trust chain that it otherwise
nvdosv
CVE-2025-15079P4MEDIUMCVSS 5.3≥ 7.58.0, < 8.18.02026-01-08
CVE-2025-15079 [MEDIUM] CWE-297 CVE-2025-15079: When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl c
When doing SSH-based transfers using either SCP or SFTP, and setting the
known_hosts file, libcurl could still mistakenly accept connecting to hosts
*not present* in the specified file if they were added as recognized in the
libssh *global* known_hosts file.
nvdosv
CVE-2016-8617P4HIGHCVSS 7.0fixed in 7.51.02018-07-31
CVE-2016-8617 [HIGH] CWE-787 CVE-2016-8617: The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.
nvdosv
CVE-2025-14017P4MEDIUMCVSS 6.3≥ 7.17.0, < 8.18.02026-01-08
CVE-2025-14017 [MEDIUM] CWE-567 CVE-2025-14017: When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.
Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.
nvdosv
CVE-2025-14524P4MEDIUMCVSS 5.3≥ 7.33.0, < 8.18.02026-01-08
CVE-2025-14524 [MEDIUM] CWE-522 CVE-2025-14524: When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-prot
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP,
POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new
target host.
nvdosv
CVE-2011-2192P4MEDIUMCVSS 4.3≥ 0, < 7.21.6-22011-07-07
CVE-2011-2192 [MEDIUM] CVE-2011-2192: The Curl_input_negotiate function in http_negotiate
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
osv
CVE-2026-7009P4MEDIUMCVSS 5.3≥ 8.17.0, < 8.20.02026-05-13
CVE-2026-7009 [MEDIUM] CWE-295 CVE-2026-7009: When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP st
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
nvd
CVE-2023-46219P4MEDIUMCVSS 5.3≥ 7.84.0, < 8.5.02023-12-12
CVE-2023-46219 [MEDIUM] CWE-311 CVE-2023-46219: When saving HSTS data to an excessively long file name, curl could end up removing all contents, mak
When saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file unaware of
the HSTS status they should otherwise use.
nvdosv
CVE-2014-3707P4MEDIUMCVSS 4.3≥ 0, < 7.38.0-32014-11-15
CVE-2014-3707 [MEDIUM] CVE-2014-3707: The curl_easy_duphandle function in libcurl 7
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
osv
CVE-2014-0015P4MEDIUMCVSS 4.0v7.10.6v7.10.7+62 more2014-02-02
CVE-2014-0015 [MEDIUM] CWE-287 CVE-2014-0015: cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
nvdosv
CVE-2013-4545P4MEDIUMCVSS 4.3v7.18.0v7.18.1+32 more2013-11-23
CVE-2013-4545 [MEDIUM] CWE-310 CVE-2013-4545: cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
nvdosv
CVE-2014-2522P4MEDIUMCVSS 4.0v7.27.0v7.28.0+8 more2014-04-18
CVE-2014-2522 [MEDIUM] CWE-20 CVE-2014-2522: curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS ba
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to sp
nvd
CVE-2025-11563P4MEDIUMCVSS 4.6≥ 0, < 8.14.1-2+deb13u2≥ 0, < 8.17.0-22026-02-25
CVE-2025-11563 [MEDIUM] CVE-2025-11563: URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user exp
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
osv
CVE-2024-6874P4MEDIUMCVSS 4.3≥ 0, < 8.9.0-12024-07-24
CVE-2024-6874 [MEDIUM] CVE-2024-6874: libcurl's URL API function [curl_url_get()](https://curl
libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then fills up the provided buffer exactly - but does not null terminate the string. This flaw
osv
CVE-2024-0853P4MEDIUMCVSS 5.3v8.5.02024-02-03
CVE-2024-0853 [MEDIUM] CWE-295 CVE-2024-0853: curl inadvertently kept the SSL session ID for connections in its cache even when the verify status
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
nvdosv
CVE-2025-5025P4MEDIUMCVSS 4.8≥ 8.5.0, < 8.14.02025-05-28
CVE-2025-5025 [MEDIUM] CWE-295 CVE-2025-5025: libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omiss
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed i
nvdosv
CVE-2022-30115P4MEDIUMCVSS 4.3≥ 7.82.0, < 7.83.12022-06-02
CVE-2022-30115 [MEDIUM] CWE-325 CVE-2022-30115: Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure cle
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the
nvdosv
CVE-2025-10966P4MEDIUMCVSS 4.3≥ 7.69.0, < 8.17.02025-11-07
CVE-2025-10966 [MEDIUM] CWE-322 CVE-2025-10966: curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was fl
curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.
This prevents curl from detecting MITM attackers and more.
nvdosv