Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

curl — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in curl, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common vulnerabilities for the open-source command-line tool curl, categorized under general software weakness types. It collects security issues reported across the curl product ecosystem, covering historical data from early adoption phases through recent years to provide a comprehensive view of the product's security landscape. Readers can discover specific advisories released by the curl project maintainers and community contributors, gaining insight into the evolution of identified weaknesses. The page allows users to understand the nature and severity of different vulnerability classes affecting libcurl and the curl binary, such as buffer overflows, protocol handling errors, and certificate verification bypasses. Additionally, you can look up the full vulnerability history for specific curl versions, tracking when issues were disclosed, patched, or mitigated. This resource serves as a reference for developers, security analysts, and system administrators to assess risk exposure, review past incidents, and ensure appropriate updates are applied. By consolidating these records, the page facilitates better understanding of the recurring threat patterns associated with curl and supports informed decision-making for secure implementation and maintenance. The aggregated data reflects publicly disclosed information and does not include internal or unreported findings. Users are encouraged to consult official curl security announcements for the most current and detailed guidance on remediation steps. This overview is intended to support ongoing security hygiene and proactive threat management strategies.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-9547 SSH improper host validation - - 2026-07-03
CVE-2026-9546 sending old referer - - 2026-07-03
CVE-2026-9545 exposing HTTP/3 early data - - 2026-07-03
CVE-2026-9080 UAF after pause in socket callback - - 2026-07-03
CVE-2026-9079 stale proxy password leak - - 2026-07-03
CVE-2026-8932 incomplete mTLS config matching in conn reuse - - 2026-07-03
CVE-2026-8927 env-set cross-proxy Digest auth state leak - - 2026-07-03
CVE-2026-8926 password leak with netrc and user in URL - - 2026-07-03
CVE-2026-8925 SASL double-free - - 2026-07-03
CVE-2026-8924 trailing dot domain super cookie - - 2026-07-03
CVE-2026-8458 wrong reuse for different services - - 2026-07-03
CVE-2026-8286 wrong STARTTLS connection reuse - - 2026-07-03
CVE-2026-12064 proto-default skips SSH verification - - 2026-07-03
CVE-2026-11856 cross-origin Digest auth state leak - - 2026-07-03
CVE-2026-11586 WS Auto-PONG memory exhaustion - - 2026-07-03
CVE-2026-11564 Native CA trust persist - - 2026-07-03
CVE-2026-11352 QUIC zero-length UDP datagrams busy-loop - - 2026-07-03
CVE-2026-10536 HTTP/2 stream-dependency tree UAF - - 2026-07-03
CVE-2026-7168 cross-proxy Digest auth state leak - - 2026-05-13
CVE-2026-7009 OCSP stapling bypass with Apple SecTrust - - 2026-05-13
CVE-2026-6429 netrc credential leak with reused proxy connection - - 2026-05-13
CVE-2026-6276 stale custom cookie host causes cookie leak - - 2026-05-13
CVE-2026-6253 proxy credentials leak over redirect-to proxy - - 2026-05-13
CVE-2026-5773 wrong reuse of SMB connection - - 2026-05-13
CVE-2026-5545 wrong reuse of HTTP Negotiate connection - - 2026-05-13
CVE-2026-4873 connection reuse ignores TLS requirement - - 2026-05-13
CVE-2026-3805 use after free in SMB connection reuse 9.1 - 2026-03-11
CVE-2026-3784 wrong proxy connection reuse with credentials 7.5 - 2026-03-11
CVE-2026-3783 token leak with redirect and netrc 6.5 - 2026-03-11
CVE-2026-1965 bad reuse of HTTP Negotiate connection 7.7 - 2026-03-11

All 89 known CVE vulnerabilities affecting curl with full Chinese analysis, references, and POCs where available.