curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.64.1版本至8.21.0版本存在会话机制问题漏洞,该漏洞源于libcurl在使用空凭据发起初始请求时,错误重用了为特定主机名建立的、使用Negotiate认证的HTTP连接,可能导致用户B的请求通过用户A先前已认证的连接发送。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet