Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

curl — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in curl, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common vulnerabilities for the open-source command-line tool curl, categorized under general software weakness types. It collects security issues reported across the curl product ecosystem, covering historical data from early adoption phases through recent years to provide a comprehensive view of the product's security landscape. Readers can discover specific advisories released by the curl project maintainers and community contributors, gaining insight into the evolution of identified weaknesses. The page allows users to understand the nature and severity of different vulnerability classes affecting libcurl and the curl binary, such as buffer overflows, protocol handling errors, and certificate verification bypasses. Additionally, you can look up the full vulnerability history for specific curl versions, tracking when issues were disclosed, patched, or mitigated. This resource serves as a reference for developers, security analysts, and system administrators to assess risk exposure, review past incidents, and ensure appropriate updates are applied. By consolidating these records, the page facilitates better understanding of the recurring threat patterns associated with curl and supports informed decision-making for secure implementation and maintenance. The aggregated data reflects publicly disclosed information and does not include internal or unreported findings. Users are encouraged to consult official curl security announcements for the most current and detailed guidance on remediation steps. This overview is intended to support ongoing security hygiene and proactive threat management strategies.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2025-11563 wcurl path traversal with percent-encoded slashes 9.1AICriticalAI2026-02-25
CVE-2025-15224 libssh key passphrase bypass without agent set 9.8 -2026-01-08
CVE-2025-15079 libssh global known_hosts override 7.5 -2026-01-08
CVE-2025-14819 OpenSSL partial chain store policy bypass 8.2 -2026-01-08
CVE-2025-14524 bearer token leak on cross-protocol redirect 4.3 -2026-01-08
CVE-2025-14017 broken TLS options for threaded LDAPS 4.3 -2026-01-08
CVE-2025-13034 No QUIC certificate pinning with GnuTLS 7.5 -2026-01-08
CVE-2025-10966 missing SFTP host verification with wolfSSH 7.4 -2025-11-07
CVE-2025-10148 predictable WebSocket mask 7.1 -2025-09-12
CVE-2025-9086 Out of bounds read for cookie path 8.1 -2025-09-12
CVE-2025-5399 WebSocket endless loop 7.5AIHighAI2025-06-07
CVE-2025-5025 No QUIC certificate pinning with wolfSSL 6.5AIMediumAI2025-05-28
CVE-2025-4947 QUIC certificate check skip with wolfSSL 7.4AIHighAI2025-05-28
CVE-2025-0725 gzip integer overflow 8.8 -2025-02-05
CVE-2025-0665 eventfd double close 7.1 -2025-02-05
CVE-2025-0167 netrc and default credential leak 5.9 -2025-02-05
CVE-2024-11053 netrc and redirect credential leak 6.5 -2024-12-11
CVE-2024-9681 HSTS subdomain overwrites parent cache entry 5.9AIMediumAI2024-11-06
CVE-2024-8096 OCSP stapling bypass with GnuTLS 7.5AIHighAI2024-09-11
CVE-2024-7264 ASN.1 date parser overread 9.1AICriticalAI2024-07-31
CVE-2024-6874 macidn punycode buffer overread 9.1AICriticalAI2024-07-24
CVE-2024-6197 freeing stack buffer in utf8asn1str 9.1AICriticalAI2024-07-24
CVE-2024-2466 TLS certificate check bypass with mbedTLS 5.9 -2024-03-27
CVE-2024-2379 QUIC certificate check bypass with wolfSSL 7.5 -2024-03-27
CVE-2024-2398 HTTP/2 push headers memory-leak --2024-03-27
CVE-2024-2004 Usage of disabled protocol 7.5 -2024-03-27
CVE-2024-0853 OCSP verification bypass with TLS session reuse 9.1 -2024-02-03
CVE-2023-46219 curl 安全漏洞 7.5 -2023-12-12
CVE-2023-46218 curl 安全漏洞 5.3 -2023-12-07
CVE-2023-38545 curl 缓冲区错误漏洞 9.1 -2023-10-18

All 89 known CVE vulnerabilities affecting curl with full Chinese analysis, references, and POCs where available.