cbcvebase.

Haxx Curl vulnerabilities

217 known vulnerabilities affecting haxx/curl.

Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14

Vulnerabilities

Page 7 of 11
CVE-2022-32208P3MEDIUMCVSS 5.9≥ 7.16.4, < 7.84.02022-07-07
CVE-2022-32208 [MEDIUM] CWE-840 CVE-2022-32208: When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wron When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
nvdosv
CVE-2017-7468P3HIGHCVSS 7.5≥ 0, < 7.52.1-52018-07-16
CVE-2017-7468 [HIGH] CVE-2017-7468: In curl and libcurl 7 In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, and may instead use the old identity which was established by the previous certificate (or no certificate). libcurl supports by default the use of TLS session id/ticket to resume previous
osv
CVE-2026-8458P3MEDIUMCVSS 6.5≥ 7.46.0, < 8.20.02026-07-03
CVE-2026-8458 [MEDIUM] CWE-488 CVE-2026-8458: libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authentica libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due
nvd
CVE-2016-9952P3HIGHCVSS 8.1≥ 7.30.0, ≤ 7.51.02018-03-12
CVE-2016-9952 [HIGH] CWE-295 CVE-2016-9952: The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in a server certificate, as demonstrated by "*.com."
nvdosv
CVE-2020-8177P3HIGHCVSS 7.8≥ 7.20.0, ≤ 7.70.02020-12-14
CVE-2020-8177 [HIGH] CWE-99 CVE-2020-8177: curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resour curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
nvdosv
CVE-2015-3148P3MEDIUMCVSS 5.0v7.10.6v7.10.7+70 more2015-04-24
CVE-2015-3148 [MEDIUM] CWE-284 CVE-2015-3148: cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, w cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
nvdosv
CVE-2021-22922P3MEDIUMCVSS 6.5≥ 7.27.0, < 7.78.02021-08-05
CVE-2021-22922 [MEDIUM] CWE-840 CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified agai When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several o
nvdosv
CVE-2022-27776P3MEDIUMCVSS 6.5fixed in 7.83.02022-06-02
CVE-2022-27776 [MEDIUM] CWE-522 CVE-2022-27776: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authenticati A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
nvdosv
CVE-2009-2417P3MEDIUMCVSS 5.9≥ 0, < 7.19.5-1.12009-08-14
CVE-2009-2417 [MEDIUM] CVE-2009-2417: lib/ssluse lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
osv
CVE-2023-46218P3MEDIUMCVSS 6.5≥ 7.46.0, ≤ 8.4.02023-12-07
CVE-2023-46218 [MEDIUM] CWE-178 CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a giv
nvdosv
CVE-2021-22947P3MEDIUMCVSS 5.9≥ 7.20.0, < 7.79.02021-09-29
CVE-2021-22947 [MEDIUM] CWE-310 CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *b
nvdosv
CVE-2017-1000100P3MEDIUMCVSS 6.5≥ 0, < 7.55.0-12017-10-05
CVE-2017-1000100 [MEDIUM] CVE-2017-1000100: When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncat When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length. This too large value is then used in th
osv
CVE-2019-5443P3HIGHCVSS 7.8≤ 7.65.12019-07-02
CVE-2019-5443 [HIGH] CWE-94 CVE-2019-5443: A non-privileged user or program can put code and a config file in a known non-privileged path (unde A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
nvd
CVE-2016-3739P3MEDIUMCVSS 5.3v7.21.0v7.21.1+35 more2016-05-20
CVE-2016-3739 [MEDIUM] CWE-20 CVE-2016-3739: The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.
nvdosv
CVE-2025-0665P3HIGHCVSS 7.0v8.11.12025-02-05
CVE-2025-0665 [HIGH] CVE-2025-0665: libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection cha libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
nvdosv
CVE-2016-8616P3MEDIUMCVSS 5.9fixed in 7.51.02018-08-01
CVE-2016-8616 [MEDIUM] CWE-592 CVE-2016-8616: A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insen A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused
nvdosv
CVE-2024-2466P3MEDIUMCVSS 6.5≥ 8.5.0, < 8.7.02024-03-27
CVE-2024-2466 [MEDIUM] CWE-297 CVE-2024-2466: libcurl did not check the server certificate of TLS connections done to a host specified as an IP ad libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTP
nvdosv
CVE-2026-3784P3MEDIUMCVSS 6.5≥ 7.7, < 8.18.02026-03-11
CVE-2026-3784 [MEDIUM] CWE-305 CVE-2026-3784: curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the ne curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.
nvdosv
CVE-2023-27535P3MEDIUMCVSS 5.9≥ 0, < 7.74.0-1.3+deb11u8≥ 0, < 7.88.1-72023-03-30
CVE-2023-27535 [MEDIUM] CVE-2023-27535: An authentication bypass vulnerability exists in libcurl <8 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CU
osv
CVE-2014-0138P4MEDIUMCVSS 6.4v7.10.6v7.10.7+63 more2014-04-15
CVE-2014-0138 [MEDIUM] CVE-2014-0138: The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) PO The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
nvdosv