Haxx Curl vulnerabilities
217 known vulnerabilities affecting haxx/curl.
Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14
Vulnerabilities
Page 8 of 11
CVE-2022-32205P4MEDIUMCVSS 4.3≥ 7.71.0, < 7.84.02022-07-07
CVE-2022-32205 [MEDIUM] CWE-770 CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl a
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to av
nvdosv
CVE-2017-1000101P4MEDIUMCVSS 6.5v7.4.1v7.35.0+30 more2017-10-05
CVE-2017-1000101 [MEDIUM] CWE-119 CVE-2017-1000101: curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterat
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. Th
nvdosv
CVE-2015-3143P4MEDIUMCVSS 5.0v7.10.6v7.10.7+69 more2015-04-24
CVE-2015-3143 [MEDIUM] CVE-2015-3143: cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remot
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
nvdosv
CVE-2015-3237P4MEDIUMCVSS 6.4v7.40.0v7.41.0+2 more2015-06-22
CVE-2015-3237 [MEDIUM] CWE-20 CVE-2015-3237: The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers t
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
nvdosv
CVE-2017-2629P4MEDIUMCVSS 6.5fixed in 7.53.02018-07-27
CVE-2017-2629 [MEDIUM] CWE-295 CVE-2017-2629: curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could
nvdosv
CVE-2023-27536P4MEDIUMCVSS 5.9≥ 0, < 7.74.0-1.3+deb11u8≥ 0, < 7.88.1-72023-03-30
CVE-2023-27536 [MEDIUM] CVE-2023-27536: An authentication bypass vulnerability exists libcurl <8
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. Th
osv
CVE-2022-27774P4MEDIUMCVSS 5.7≥ 4.9, ≤ 7.82.02022-06-02
CVE-2022-27774 [MEDIUM] CWE-522 CVE-2022-27774: An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
nvdosv
CVE-2017-1000099P4MEDIUMCVSS 6.5≥ 0, < 7.55.0-r02017-10-05
CVE-2017-1000099 [MEDIUM] CVE-2017-1000099: When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could lead to other private data from the heap to get inadvertently dis
osv
CVE-2021-22876P4MEDIUMCVSS 5.3≥ 0, < 7.47.0-1ubuntu2.19≥ 0, < 7.58.0-2ubuntu3.13+1 more2021-03-31
CVE-2021-22876 [MEDIUM] curl vulnerabilities
curl vulnerabilities
Viktor Szakats discovered that curl did not strip off user credentials
from referrer header fields. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2021-22876)
Mingtao Yang discovered that curl incorrectly handled session tickets when
using an HTTPS proxy. A remote attacker in control of an HTTPS proxy could
use this issue to bypass certificate checks and intercept communications.
This issue
osv
CVE-2023-23915P4MEDIUMCVSS 6.5≥ 7.77.0, < 7.88.02023-02-23
CVE-2023-23915 [MEDIUM] CWE-319 CVE-2023-23915: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could c
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS
nvdosv
CVE-2024-8096P4MEDIUMCVSS 6.5≥ 7.41.0, < 8.10.02024-09-11
CVE-2024-8096 [MEDIUM] CWE-295 CVE-2024-8096: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP sta
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not
nvdosv
CVE-2023-28321P4MEDIUMCVSS 5.9fixed in 8.1.02023-05-26
CVE-2023-28321 [MEDIUM] CWE-295 CVE-2023-28321: An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports match
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private wildcard matching function would mat
nvdosv
CVE-2026-6253P4MEDIUMCVSS 5.9≥ 7.14.1, < 8.20.02026-05-13
CVE-2026-6253 [MEDIUM] CWE-522 CVE-2026-6253: curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen whe
curl might erroneously pass on credentials for a first proxy to a second
proxy.
This can happen when the following conditions are true:
1. curl is setup to use specific different proxies for different URL schemes
2. the first proxy needs credentials
3. the second proxy uses no credentials
4. while using the first proxy (using say `http://`), curl is
nvd
CVE-2026-4873P4MEDIUMCVSS 5.9≥ 7.20.0, < 8.20.02026-05-13
CVE-2026-4873 [MEDIUM] CWE-319 CVE-2026-4873: A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted c
A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to that same host bypasses the TLS requirement and instead transmit data
unencrypted.
nvd
CVE-2025-13034P4MEDIUMCVSS 5.9≥ 8.8.0, < 8.18.02026-01-08
CVE-2025-13034 [MEDIUM] CWE-295 CVE-2025-13034: When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, cur
When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`
with the curl tool, curl should check the public key of the server certificate
to verify the peer.
This check was skipped in a certain condition that would then make curl allow
the connection without performing the proper check, thus not noticing a
possible impostor. To sk
nvdosv
CVE-2016-4802P4HIGHCVSS 7.8≤ 7.49.02016-06-24
CVE-2016-4802 [HIGH] CWE-264 CVE-2016-4802: Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SS
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.
nvd
CVE-2015-3236P4MEDIUMCVSS 5.0v7.40.0v7.41.0+2 more2015-06-22
CVE-2015-3236 [MEDIUM] CWE-200 CVE-2015-3236: cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvdosv
CVE-2014-3613P4MEDIUMCVSS 5.0≤ 7.37.1v7.31.0+6 more2014-11-18
CVE-2014-3613 [MEDIUM] CWE-310 CVE-2014-3613: cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which a
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
nvdosv
CVE-2021-22925P4MEDIUMCVSS 5.3≥ 7.7, < 7.78.02021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvdosv
CVE-2025-4947P4MEDIUMCVSS 6.5≥ 8.8.0, < 8.14.02025-05-28
CVE-2025-4947 [MEDIUM] CWE-295 CVE-2025-4947: libcurl accidentally skips the certificate verification for QUIC connections when connecting to a ho
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
nvdosv