curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.45.0版本至8.21.0版本存在加密问题漏洞,该漏洞源于配置CURLOPT_PINNEDPUBLICKEY时同时设置CURLOPT_SSL_VERIFYPEER=0和CURLOPT_SSL_VERIFYHOST=0禁用标准对端验证,未能在没有提供服务器证书的连接上强制执行公钥固定,可能导致未认证连接绕过固定检查成功建立。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet