Haxx Curl vulnerabilities
217 known vulnerabilities affecting haxx/curl.
Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14
Vulnerabilities
Page 4 of 11
CVE-2017-8817P3CRITICALCVSS 9.8≥ 7.21.0, ≤ 7.56.12017-11-29
CVE-2017-8817 [CRITICAL] CWE-125 CVE-2017-8817: The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denia
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
nvdosv
CVE-2018-1000301P3CRITICALCVSS 9.1≥ 7.20.0, ≤ 7.59.02018-05-24
CVE-2018-1000301 [CRITICAL] CWE-125 CVE-2018-1000301: curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerabi
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
nvdosv
CVE-2017-1000254P3HIGHCVSS 7.5≥ 0, < 7.56.1-12017-10-06
CVE-2017-1000254 [HIGH] CVE-2017-1000254: libcurl may read outside of a heap allocated buffer when doing FTP
libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory with the `PWD` command. The server then responds with a 257 response containing the path, inside double quotes. The returned path name is then kept by libcurl for subsequent uses. Due to a flaw
osv
CVE-2026-8286P3HIGHCVSS 8.1≥ 7.30.0, < 8.21.02026-07-03
CVE-2026-8286 [HIGH] CWE-295 CVE-2026-8286: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.
nvd
CVE-2016-9586P3HIGHCVSS 8.1fixed in 7.52.02018-04-23
CVE-2016-9586 [HIGH] CWE-122 CVE-2016-9586: curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point outp
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
nvdosv
CVE-2023-23914P3CRITICALCVSS 9.1≥ 7.77.0, < 7.88.02023-02-23
CVE-2023-23914 [CRITICAL] CWE-319 CVE-2023-23914: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could c
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would howe
nvdosv
CVE-2026-18924P3CRITICALCVSS 9.1≥ 7.44.0, < 8.22.02026-09-06
CVE-2026-18924 [CRITICAL] CWE-416 CVE-2026-18924: A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share c
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.
nvd
CVE-2018-16840P3CRITICALCVSS 9.8≥ 7.59.0, < 7.62.02018-10-31
CVE-2018-16840 [CRITICAL] CWE-416 CVE-2018-16840: A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related
A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that
nvdosv
CVE-2024-7264P3MEDIUMCVSS 6.5≥ 0, < 8.9.1-r02024-07-31
CVE-2024-7264 [MEDIUM] CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the *time fraction*, leading to
a `strlen()` getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a cra
osv
CVE-2026-12064P3HIGHCVSS 7.5≥ 7.81.0, < 8.21.02026-07-03
CVE-2026-12064 [HIGH] CWE-297 CVE-2026-12064: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a dis
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conve
nvd
CVE-2026-9547P3HIGHCVSS 7.4≥ 7.69.0, < 8.21.02026-07-03
CVE-2026-9547 [HIGH] CWE-297 CVE-2026-9547: When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURL
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of reje
nvd
CVE-2026-11352P3HIGHCVSS 7.5≥ 8.18.0, < 8.21.02026-07-03
CVE-2026-11352 [HIGH] CWE-835 CVE-2026-11352: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote de
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote denial of service against a curl or libcurl client.
Because the helper function discards zero-length UDP datagrams before counting
them toward the per-call packet budget, a connected QUIC peer can continuously
stream empty datagrams to indefinitely stall
nvd
CVE-2026-9545P3HIGHCVSS 7.5≥ 8.11.0, < 8.21.02026-07-03
CVE-2026-9545 [HIGH] CWE-200 CVE-2026-9545: In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it m
In this scenario, libcurl first uses a proper HTTP/3 server for the initial
transfers, and when it makes a second transfer to the same site it has been
replaced by the attacker's impostor machine - without a valid certificate.
When libcurl returns to the hostname the second time with a cached SSL session
(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled)
nvd
CVE-2026-80230P3HIGHCVSS 7.5≥ 7.45.0, < 8.22.02026-09-06
CVE-2026-80230 [HIGH] CWE-295 CVE-2026-80230: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verificati
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions a
nvd
CVE-2016-8624P3HIGHCVSS 7.5fixed in 7.51.02018-07-31
CVE-2016-8624 [HIGH] CWE-20 CVE-2016-8624: curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host
curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request th
nvdosv
CVE-2016-8615P3HIGHCVSS 7.5fixed in 7.51.02018-08-01
CVE-2016-8615 [HIGH] CWE-99 CVE-2016-8615: A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
nvdosv
CVE-2026-5545P3MEDIUMCVSS 6.5≥ 7.10.6, < 8.20.02026-05-13
CVE-2026-5545 [MEDIUM] CWE-305 CVE-2026-5545: libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTT
libcurl might in some circumstances reuse the wrong connection when asked to
do an authenticated HTTP(S) request after a Negotiate-authenticated one, when
both use the same host.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria
nvd
CVE-2015-3144P3CRITICALCVSS 9.0v7.37.0v7.37.1+4 more2015-04-24
CVE-2015-3144 [CRITICAL] CWE-119 CVE-2015-3144: The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an i
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
nvdosv
CVE-2023-28319P3HIGHCVSS 7.5fixed in 8.1.02023-05-26
CVE-2023-28319 [HIGH] CWE-416 CVE-2023-28319: A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the err
nvdosv
CVE-2003-1605P3HIGHCVSS 7.5≥ 7.1.0, < 7.10.72018-08-23
CVE-2003-1605 [HIGH] CWE-255 CVE-2003-1605: curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
nvdosv