curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.82.0版本至8.21.0版本存在授权问题漏洞,该漏洞源于libcurl的LDAP身份验证中SASL协商过程存在缺陷,不完整的握手序列可能被误解为成功的加密验证,导致中间人攻击者能够注入提前或捷径响应,绕过完整的对等验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab |
No comments yet