Haxx Curl vulnerabilities
217 known vulnerabilities affecting haxx/curl.
Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14
Vulnerabilities
Page 11 of 11
CVE-2018-16980P4MEDIUMCVSS 6.1≥ 0, < 7.64.0-r02018-09-12
CVE-2018-16980 [MEDIUM] CVE-2018-16980: dotCMS V5
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
osv
CVE-2021-22924P4LOWCVSS 3.7≥ 0, < 7.74.0-1.3+deb11u2≥ 0, < 7.79.1-12021-08-05
CVE-2021-22924 [LOW] CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connectio
osv
CVE-2023-38546P4LOWCVSS 3.7≥ 0, < 8.4.0-r02023-10-18
CVE-2023-38546 [LOW] CVE-2023-38546: This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met
This flaw allows an attacker to insert cookies at will into a running program
using libcurl, if the specific series of conditions are met.
libcurl performs transfers. In its API, an application creates "easy handles"
that are the individual handles for single transfers.
libcurl provides a function call that duplicates en
osv
CVE-2020-8284P4LOWCVSS 3.7≤ 7.73.02020-12-14
CVE-2020-8284 [LOW] CWE-200 CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting ba
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
nvdosv
CVE-2019-5435P4LOWCVSS 3.7≥ 7.62.0, ≤ 7.64.12019-05-28
CVE-2019-5435 [LOW] CWE-131 CVE-2019-5435: An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and includin
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
nvdosv
CVE-2021-22898P4LOWCVSS 3.1≥ 7.7, ≤ 7.76.12021-06-11
CVE-2021-22898 [LOW] CWE-200 CVE-2021-22898: curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, kn
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the se
nvdosv
CVE-2013-6422P4MEDIUMCVSS 4.0≥ 0, < 7.34.0-12013-12-23
CVE-2013-6422 [MEDIUM] CVE-2013-6422: The GnuTLS backend in libcurl 7
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
osv
CVE-2021-22890P4LOWCVSS 3.7≥ 0, < 7.74.0-1.22021-04-01
CVE-2021-22890 [LOW] CVE-2021-22890: curl 7
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the host handshake. When confusing the tickets, a HTTPS proxy can trick libcurl to use the wrong session tic
osv
CVE-2023-28322P4LOWCVSS 3.7fixed in 8.1.02023-05-26
CVE-2023-28322 [LOW] CWE-200 CVE-2023-28322: An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surp
nvdosv
CVE-2024-2004P4LOWCVSS 3.5≥ 7.85.0, < 8.7.02024-03-27
CVE-2024-2004 [LOW] CWE-436 CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the defaul
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.s
nvdosv
CVE-2022-35252P4LOWCVSS 3.7fixed in 7.85.02022-09-23
CVE-2022-35252 [LOW] CWE-20 CVE-2022-35252: When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using contr
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
nvdosv
CVE-2024-11053P4LOWCVSS 3.4≥ 7.76.0, < 8.11.12024-12-11
CVE-2024-11053 [LOW] CVE-2024-11053: When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak
When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has an entry that matches
the redirect target hostname but the entry either omits just the password or
omits both login
nvdosv
CVE-2025-0167P4LOWCVSS 3.4≥ 7.76.0, < 8.12.02025-02-05
CVE-2025-0167 [LOW] CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
nvdosv
CVE-2025-15224P4LOWCVSS 3.1≥ 7.58.0, < 8.18.02026-01-08
CVE-2025-15224 [LOW] CWE-287 CVE-2025-15224: When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication,
When doing SSH-based transfers using either SCP or SFTP, and asked to do
public key authentication, curl would wrongly still ask and authenticate using
a locally running SSH agent.
nvdosv
CVE-2005-4077P4MEDIUMCVSS 4.6≥ 0, < 7.15.1-12005-12-08
CVE-2005-4077 [MEDIUM] CVE-2005-4077: Multiple off-by-one errors in the cURL library (libcurl) 7
Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 allow local users to trigger a buffer overflow and cause a denial of service or bypass PHP security restrictions via certain URLs that (1) are malformed in a way that prevents a terminating null byte from being added to either a hostname or path buffer, or (2) contain a "?" separator in the hostname portion, which causes a
osv
CVE-2020-19909P4LOWCVSS 3.3v7.65.22023-08-22
CVE-2020-19909 [LOW] CWE-190 CVE-2020-19909: Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than wh
nvdosv
CVE-2017-7407P4LOWCVSS 2.4v7.53.12017-04-03
CVE-2017-7407 [LOW] CWE-119 CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attacker
The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.
nvdosv
← Previous11 / 11