CVEs (61)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Haxx Netapp8Curl Hci Baseboard Management ControllerHci H610c Firmware+5 moreJun 17, 2026 Feb 5, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would ma...Show more |
2Google Haxx2Libcurl Nest Mini FirmwareJun 17, 2026 Aug 19, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traff...Show more |
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fractio...Show more |
libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside o...Show more |
libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack b...Show more |
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" th...Show more |
4Fedoraproject HaxxMicrosoft+1 more13Active Iq Unified Manager FedoraLibcurl+10 moreJun 17, 2026 Oct 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl...Show more |
6Broadcom DebianFedoraproject+3 more11Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+8 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcur...Show more |
4Broadcom HaxxNetapp+1 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareClustered Data Ontap+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indi...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the...Show more |
5Debian FedoraprojectHaxx+2 more10Active Iq Unified Manager Debian LinuxFedora+7 moreJun 17, 2026 Mar 30, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in...Show more |
8Apple DebianFedoraproject+5 more17Cloud Backup Clustered Data OntapDebian Linux+14 moreJun 17, 2026 Sep 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also...Show more |
7Debian FedoraprojectHaxx+4 more33Cloud Backup Clustered Data OntapDebian Linux+30 moreJun 17, 2026 Aug 5, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into ac...Show more |
8Broadcom DebianFedoraproject+5 more11Communications Billing And Revenue Management Debian LinuxEssbase+8 moreJun 17, 2026 Apr 1, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confus...Show more |
8Broadcom DebianFedoraproject+5 more12Communications Billing And Revenue Management Debian LinuxEssbase+9 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials f...Show more |
8Apple DebianFedoraproject+5 more17Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+14 moreJun 17, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. |
9Apple DebianFedoraproject+6 more22Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+19 moreJun 17, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. |
5Debian HaxxOracle+2 more5Communications Cloud Native Core Policy Debian LinuxLibcurl+2 moreJun 17, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. |
7Debian F5Fedoraproject+4 more11Debian Linux Enterprise Manager Ops CenterFedora+8 moreJun 17, 2026 May 28, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
5Canonical DebianHaxx+2 more7Clustered Data Ontap Communications Operations MonitorDebian Linux+4 moreJun 17, 2026 Feb 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no...Show more |