cbcvebase.

Haxx Curl vulnerabilities

217 known vulnerabilities affecting haxx/curl.

Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14

Vulnerabilities

Page 5 of 11
CVE-2026-3805P3HIGHCVSS 7.5≥ 8.13.0, < 8.19.02026-03-11
CVE-2026-3805 [HIGH] CWE-416 CVE-2026-3805: When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointi When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
nvdosv
CVE-2026-9546P3HIGHCVSS 7.5≥ 8.18.0, < 8.21.02026-07-03
CVE-2026-9546 [HIGH] CWE-200 CVE-2026-9546: A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result, the previous referrer string was erroneously reused and sent in subsequent requests, potentially lea
nvd
CVE-2026-80255P3HIGHCVSS 7.5≥ 8.13.0, < 8.22.02026-09-06
CVE-2026-80255 [HIGH] CWE-201 CVE-2026-80255: A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) imm A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
nvd
CVE-2020-8286P3HIGHCVSS 7.5≥ 0, < 7.74.0-12020-12-14
CVE-2020-8286 [HIGH] CVE-2020-8286: curl 7 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
osv
CVE-2024-6197P3HIGHCVSS 7.5≥ 0, < 8.9.0-12024-07-24
CVE-2024-6197 [HIGH] CVE-2024-6197: libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available
osv
CVE-2020-8231P3HIGHCVSS 7.5≥ 0, < 7.47.0-1ubuntu2.18≥ 0, < 7.58.0-2ubuntu3.12+1 more2020-12-09
CVE-2020-8231 [HIGH] curl vulnerabilities curl vulnerabilities Marc Aldorasi discovered that curl incorrectly handled the libcurl CURLOPT_CONNECT_ONLY option. This could result in data being sent to the wrong destination, possibly exposing sensitive information. This issue only affected Ubuntu 20.10. (CVE-2020-8231) Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV responses. An attacker could possibly use this issue to trick curl into connecting to an arbitrary IP address
osv
CVE-2022-42916P3HIGHCVSS 7.5≥ 7.77.0, < 7.86.02022-10-29
CVE-2022-42916 [HIGH] CWE-319 CVE-2022-42916: In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using it In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replac
nvdosv
CVE-2025-5399P3HIGHCVSS 7.5≥ 8.13.0, < 8.14.12025-06-07
CVE-2025-5399 [HIGH] CWE-835 CVE-2025-5399: Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted pac Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using application.
nvdosv
CVE-2026-11586P3HIGHCVSS 7.5≥ 8.16.0, < 8.21.02026-07-03
CVE-2026-11586 [HIGH] CWE-770 CVE-2026-11586: By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
nvd
CVE-2026-8932P3HIGHCVSS 7.5≥ 7.7, < 8.21.02026-07-03
CVE-2026-8932 [HIGH] CWE-305 CVE-2026-8932: libcurl would reuse a previously created connection even when some mTLS config related option had be libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from
nvd
CVE-2018-16842P3CRITICALCVSS 9.1≥ 7.14.1, ≤ 7.61.12018-10-31
CVE-2018-16842 [CRITICAL] CWE-125 CVE-2018-16842: Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
nvdosv
CVE-2018-16890P3HIGHCVSS 7.5≥ 0, < 7.64.0-12019-02-06
CVE-2018-16890 [HIGH] CVE-2018-16890: libcurl versions from 7 libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer r
osv
CVE-2022-27778P3HIGHCVSS 8.1v7.83.02022-06-02
CVE-2022-27778 [HIGH] CWE-706 CVE-2022-27778: A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `- A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
nvdosv
CVE-2020-8169P3HIGHCVSS 7.5≥ 7.62.0, ≤ 7.70.02020-12-14
CVE-2020-8169 [HIGH] CWE-200 CVE-2020-8169: curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
nvdosv
CVE-2018-1000121P3HIGHCVSS 7.5≥ 7.21.0, ≤ 7.58.02018-03-14
CVE-2018-1000121 [HIGH] CWE-476 CVE-2018-1000121: A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
nvdosv
CVE-2022-27775P3HIGHCVSS 7.5≥ 7.65.0, ≤ 7.82.02022-06-02
CVE-2022-27775 [HIGH] CWE-200 CVE-2022-27775: An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
nvdosv
CVE-2022-27782P3HIGHCVSS 7.5fixed in 7.83.12022-06-02
CVE-2022-27782 [HIGH] CWE-840 CVE-2022-27782: libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been ch libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match che
nvdosv
CVE-2026-80231P3HIGHCVSS 7.5≥ 7.71.0, < 8.22.02026-09-06
CVE-2026-80231 [HIGH] CWE-488 CVE-2026-80231: A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname eve A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
nvd
CVE-2025-0725P3HIGHCVSS 7.3≥ 7.10.5, < 8.12.02025-02-05
CVE-2025-0725 [HIGH] CWE-120 CVE-2025-0725: When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
nvdosv
CVE-2026-80229P3HIGHCVSS 7.5≥ 8.14.0, < 8.22.02026-09-06
CVE-2026-80229 [HIGH] CWE-416 CVE-2026-80229: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their or When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this c
nvd
Haxx Curl vulnerabilities | cvebase