curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0版本、8.20.0版本、8.19.0版本、8.18.0版本、8.17.0版本、8.16.0版本、8.15.0版本、8.14.1版本和8.14.0版本存在资源管理错误漏洞,该漏洞源于通过libcurl的multi接口执行传输时,在OpenSSL 3 provider配置下,libcurl将已分配的库上下文附加到easy handle状态并传递给OpenSSL,但未获取所有权引用,过早销毁easy han
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet