curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0及之前版本存在加密问题漏洞,该漏洞源于使用wolfSSL后端时,在启用CA缓存且CURLOPT_SSL_CTX_FUNCTION回调替换信任存储后,libcurl会在回调返回后静默重新安装缓存存储,导致被缓存存储信任但被回调所选存储拒绝的证书被错误接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet