curl是瑞典cURL团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.10.6版本至8.20.0及之前版本存在授权问题漏洞,该漏洞源于在处理Digest认证时,复用同一句柄将HTTP原始值从hostA更改至hostB,导致libcurl错误地将原本属于hostA的Authorization标头字段传递给hostB。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | |
| CVE-2026-8458 | wrong reuse for different services | |
| CVE-2026-8925 | SASL double-free | |
| CVE-2026-8286 | wrong STARTTLS connection reuse | |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | |
| CVE-2026-8926 | password leak with netrc and user in URL | |
| CVE-2026-8924 | trailing dot domain super cookie | |
| CVE-2026-12064 | proto-default skips SSH verification | |
| CVE-2026-11352 | QUIC zero-length UDP datagrams busy-loop | |
| CVE-2026-9546 | sending old referer | |
| CVE-2026-9545 | exposing HTTP/3 early data | |
| CVE-2026-9080 | UAF after pause in socket callback | |
| CVE-2026-9547 | SSH improper host validation | |
| CVE-2026-9079 | stale proxy password leak | |
| CVE-2026-11564 | Native CA trust persist | |
| CVE-2026-11586 | WS Auto-PONG memory exhaustion |
No comments yet