Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CURL — Vulnerabilities & Security Advisories 74

Browse all 74 CVE security advisories affecting CURL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CURL is a widely utilized command-line tool and library for transferring data with URL syntax, supporting protocols like HTTP, HTTPS, and FTP. Its ubiquity in automation scripts and embedded systems makes it a frequent target for attackers seeking initial access or data exfiltration. Historically, vulnerabilities in the software have predominantly involved buffer overflows, integer overflows, and improper input validation, leading to potential remote code execution or denial-of-service conditions. While cross-site scripting is less relevant due to its non-browser nature, privilege escalation risks arise when executed with elevated permissions. Notable incidents include critical flaws allowing attackers to bypass security checks or execute arbitrary commands through crafted URLs. With 39 recorded CVEs, maintaining updated versions is essential to mitigate these persistent risks associated with its extensive protocol support and deep integration into global infrastructure.

Top products by CURL: curl
CVE ID Title CVSS Severity Published
CVE-2026-82209 domain-scoped PSL domain cookie — curl CWE-201 - - 2026-09-06
CVE-2026-82208 wolfSSL CA-cache hit overrides callback — curl CWE-295 - - 2026-09-06
CVE-2026-80255 secure cookie attribute bypass with tab — curl CWE-201 - - 2026-09-06
CVE-2026-80231 native CA store conn reuse — curl CWE-488 - - 2026-09-06
CVE-2026-80230 OpenSSL pinning bypass — curl CWE-295 - - 2026-09-06
CVE-2026-80229 OpenSSL provider use-after-free — curl CWE-416 - - 2026-09-06
CVE-2026-19931 Negotiate ambient user conn reuse — curl CWE-488 - - 2026-09-06
CVE-2026-18924 HTTP/2 server push UAF — curl CWE-416 - - 2026-09-06
CVE-2026-13608 OpenLDAP SASL authentication bypass — curl CWE-923 - - 2026-09-06
CVE-2026-9547 SSH improper host validation — curl CWE-297 - - 2026-07-03
CVE-2026-9546 sending old referer — curl CWE-200 - - 2026-07-03
CVE-2026-9545 exposing HTTP/3 early data — curl CWE-200 - - 2026-07-03
CVE-2026-9080 UAF after pause in socket callback — curl CWE-416 - - 2026-07-03
CVE-2026-9079 stale proxy password leak — curl CWE-522 - - 2026-07-03
CVE-2026-8932 incomplete mTLS config matching in conn reuse — curl CWE-305 - - 2026-07-03
CVE-2026-8927 env-set cross-proxy Digest auth state leak — curl CWE-294 - - 2026-07-03
CVE-2026-8926 password leak with netrc and user in URL — curl CWE-522 - - 2026-07-03
CVE-2026-8925 SASL double-free — curl CWE-415 - - 2026-07-03
CVE-2026-8924 trailing dot domain super cookie — curl CWE-201 - - 2026-07-03
CVE-2026-8458 wrong reuse for different services — curl CWE-488 - - 2026-07-03
CVE-2026-8286 wrong STARTTLS connection reuse — curl CWE-295 - - 2026-07-03
CVE-2026-12064 proto-default skips SSH verification — curl CWE-297 - - 2026-07-03
CVE-2026-11856 cross-origin Digest auth state leak — curl CWE-294 - - 2026-07-03
CVE-2026-11586 WS Auto-PONG memory exhaustion — curl CWE-770 - - 2026-07-03
CVE-2026-11564 Native CA trust persist — curl CWE-295 - - 2026-07-03
CVE-2026-11352 QUIC zero-length UDP datagrams busy-loop — curl CWE-835 - - 2026-07-03
CVE-2026-10536 HTTP/2 stream-dependency tree UAF — curl CWE-416 - - 2026-07-03
CVE-2026-7168 cross-proxy Digest auth state leak — curl CWE-294 - - 2026-05-13
CVE-2026-7009 OCSP stapling bypass with Apple SecTrust — curl - - 2026-05-13
CVE-2026-6429 netrc credential leak with reused proxy connection — curl CWE-200 - - 2026-05-13

This page lists every published CVE security advisory associated with CURL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.