Haxx Curl vulnerabilities
217 known vulnerabilities affecting haxx/curl.
Total CVEs
217
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL42HIGH77MEDIUM84LOW14
Vulnerabilities
Page 9 of 11
CVE-2026-7168P4MEDIUMCVSS 5.3≥ 7.12.0, < 8.20.02026-05-13
CVE-2026-7168 [MEDIUM] CWE-294 CVE-2026-7168: Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** au
Successfully using libcurl to do a transfer over a specific HTTP proxy
(`proxyA`) with **Digest** authentication and then changing the proxy host to
a second one (`proxyB`) for a second transfer, reusing the same handle, makes
libcurl wrongly pass on the `Proxy-Authorization:` header field meant for
`proxyA`, to `proxyB`.
nvd
CVE-2026-6429P4MEDIUMCVSS 5.3≥ 7.14.0, < 8.20.02026-05-13
CVE-2026-6429 [MEDIUM] CWE-200 CVE-2026-6429: When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could l
When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, libcurl could leak the password used for the first host to the
followed-to host under certain circumstances.
nvd
CVE-2014-0139P4MEDIUMCVSS 5.8v7.10.6v7.10.7+63 more2014-04-15
CVE-2014-0139 [MEDIUM] CWE-310 CVE-2014-0139: cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
nvdosv
CVE-2022-35260P4MEDIUMCVSS 6.5≥ 7.84.0, < 7.86.02022-12-05
CVE-2022-35260 [MEDIUM] CWE-125 CVE-2022-35260: curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 cons
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also
nvdosv
CVE-2023-23916P4MEDIUMCVSS 6.5≥ 7.57.0, < 7.88.02023-02-23
CVE-2023-23916 [MEDIUM] CWE-770 CVE-2023-23916: An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemente
nvdosv
CVE-2024-2379P4MEDIUMCVSS 6.3v8.6.02024-03-27
CVE-2024-2379 [MEDIUM] CWE-295 CVE-2024-2379: libcurl skips the certificate verification for a QUIC connection under certain conditions, when buil
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.
nvdosv
CVE-2014-3620P4MEDIUMCVSS 5.0≤ 7.37.1v7.31.0+6 more2014-11-18
CVE-2014-3620 [MEDIUM] CWE-310 CVE-2014-3620: cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cooki
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
nvdosv
CVE-2021-22897P4MEDIUMCVSS 5.3≥ 7.61.0, ≤ 7.76.12021-06-11
CVE-2021-22897 [MEDIUM] CWE-840 CVE-2021-22897: curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake i
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if an application sets up multiple
nvdosv
CVE-2022-27779P4MEDIUMCVSS 5.3≥ 7.82.0, < 7.83.12022-06-02
CVE-2022-27779 [MEDIUM] CWE-201 CVE-2022-27779: libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided wi
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more rudimentary check exists to atleast preven
nvdosv
CVE-2023-27537P4MEDIUMCVSS 5.9≥ 0, < 7.88.1-72023-03-30
CVE-2023-27537 [MEDIUM] CVE-2023-27537: A double free vulnerability exists in libcurl <8
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
osv
CVE-2021-22923P4MEDIUMCVSS 5.3≥ 7.27.0, < 7.78.02021-08-05
CVE-2021-22923 [MEDIUM] CWE-319 CVE-2021-22923: When curl is instructed to get content using the metalink feature, and a user name and password are
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and witho
nvdosv
CVE-2026-3783P4MEDIUMCVSS 5.3≥ 7.33.0, < 8.19.02026-03-11
CVE-2026-3783 [MEDIUM] CWE-522 CVE-2026-3783: When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect t
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer
performs a redirect to a second URL, curl could leak that token to the second
hostname under some circumstances.
If the hostname that the first request is redirected to has information in the
used .netrc file, with either of the `machine` or `default` keywords, curl
would
nvdosv
CVE-2023-28320P4MEDIUMCVSS 5.9fixed in 8.1.02023-05-26
CVE-2023-28320 [MEDIUM] CWE-400 CVE-2023-28320: A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several differe
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this, libcurl used a global buffer that wa
nvdosv
CVE-2022-43552P4MEDIUMCVSS 5.9fixed in 7.87.02023-02-09
CVE-2022-43552 [MEDIUM] CWE-416 CVE-2022-43552: A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all p
A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfe
nvdosv
CVE-2023-27538P4MEDIUMCVSS 5.5≥ 0, < 7.74.0-1.3+deb11u8≥ 0, < 7.88.1-72023-03-30
CVE-2023-27538 [MEDIUM] CVE-2023-27538: An authentication bypass vulnerability exists in libcurl prior to v8
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the confi
osv
CVE-2010-0734P4MEDIUMCVSS 6.8≥ 0, < 7.20.0-12010-03-19
CVE-2010-0734 [MEDIUM] CVE-2010-0734: content_encoding
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
osv
CVE-2015-3153P4MEDIUMCVSS 5.0≤ 7.42.02015-05-01
CVE-2015-3153 [MEDIUM] CWE-200 CVE-2015-3153: The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the p
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
nvdosv
CVE-2025-10148P4MEDIUMCVSS 5.3≥ 8.11.0, < 8.16.02025-09-12
CVE-2025-10148 [MEDIUM] CWE-340 CVE-2025-10148: curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the spec
curl's WebSocket code did not update the 32-bit mask pattern for each new
outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.
A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by a
nvdosv
CVE-2014-8150P4MEDIUMCVSS 4.3≥ 0, < 7.38.0-42015-01-15
CVE-2014-8150 [MEDIUM] CVE-2014-8150: CRLF injection vulnerability in libcurl 6
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
osv
CVE-2013-1944P4MEDIUMCVSS 5.0≤ 7.29.0v6.0+99 more2013-04-29
CVE-2013-1944 [MEDIUM] CWE-200 CVE-2013-1944: The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the pat
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
nvdosv