Skip to main content

Vendor/product archive

haxx / libcurl CVEs

Beta · best-effort

61 CVEs tagged to haxx / libcurl10 Critical, 16 High, 31 Medium, 4 Low, 0 Unrated.

CVE-2025-0725

Published Feb 5, 2025

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an atta…

CVSS 7.3 · High
evidence mentions
8
Buzz score
36.5

CVE-2024-7264

Published Jul 31, 2024

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up usi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6874

Published Jul 24, 2024

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6197

Published Jul 24, 2024

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-38546

Published Oct 18, 2023

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API,…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2023-38545

Published Oct 18, 2023

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the a…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
33.8

CVE-2023-27538

Published Mar 30, 2023

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified,…

CVSS 5.5 · Medium

CVE-2023-27537

Published Mar 30, 2023

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing acro…

CVSS 5.9 · Medium

CVE-2023-27536

Published Mar 30, 2023

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due…

CVSS 5.9 · Medium

CVE-2023-27535

Published Mar 30, 2023

An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Pr…

CVSS 5.9 · Medium

CVE-2021-22890

Published Apr 1, 2021

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HT…

CVSS 3.7 · Low

CVE-2021-22876

Published Apr 1, 2021

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libc…

CVSS 5.3 · Medium

CVE-2019-5436

Published May 28, 2019

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS 7.8 · High

CVE-2018-16890

Published Feb 6, 2019

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode…

CVSS 7.5 · High

CVE-2016-8622

Published Jul 31, 2018

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-7468

Published Jul 16, 2018

In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server b…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 61 CVEsPage 1 of 3