curl是瑞典cURL团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl存在信息泄露漏洞,该漏洞源于Cookie解析逻辑缺陷,允许恶意HTTP服务器设置绕过公共后缀列表检查的“超级cookie”,从而使攻击者控制的源注入curl随后作用域并传输到无关第三方域的Cookie。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9546 | sending old referer | |
| CVE-2026-8932 | incomplete mTLS config matching in conn reuse | |
| CVE-2026-8458 | wrong reuse for different services | |
| CVE-2026-8925 | SASL double-free | |
| CVE-2026-8286 | wrong STARTTLS connection reuse | |
| CVE-2026-8927 | env-set cross-proxy Digest auth state leak | |
| CVE-2026-8926 | password leak with netrc and user in URL | |
| CVE-2026-12064 | proto-default skips SSH verification | |
| CVE-2026-10536 | HTTP/2 stream-dependency tree UAF | |
| CVE-2026-11352 | QUIC zero-length UDP datagrams busy-loop | |
| CVE-2026-9545 | exposing HTTP/3 early data | |
| CVE-2026-9080 | UAF after pause in socket callback | |
| CVE-2026-9547 | SSH improper host validation | |
| CVE-2026-9079 | stale proxy password leak | |
| CVE-2026-11564 | Native CA trust persist | |
| CVE-2026-11856 | cross-origin Digest auth state leak | |
| CVE-2026-11586 | WS Auto-PONG memory exhaustion |
No comments yet