Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CURL — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting CURL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CURL is a widely utilized command-line tool and library for transferring data with URL syntax, supporting protocols like HTTP, HTTPS, and FTP. Its ubiquity in automation scripts and embedded systems makes it a frequent target for attackers seeking initial access or data exfiltration. Historically, vulnerabilities in the software have predominantly involved buffer overflows, integer overflows, and improper input validation, leading to potential remote code execution or denial-of-service conditions. While cross-site scripting is less relevant due to its non-browser nature, privilege escalation risks arise when executed with elevated permissions. Notable incidents include critical flaws allowing attackers to bypass security checks or execute arbitrary commands through crafted URLs. With 39 recorded CVEs, maintaining updated versions is essential to mitigate these persistent risks associated with its extensive protocol support and deep integration into global infrastructure.

Top products by CURL: curl
CVE ID Title CVSS Severity Published
CVE-2026-9547 SSH improper host validation — curl - - 2026-07-03
CVE-2026-9546 sending old referer — curl - - 2026-07-03
CVE-2026-9545 exposing HTTP/3 early data — curl - - 2026-07-03
CVE-2026-9080 UAF after pause in socket callback — curl - - 2026-07-03
CVE-2026-9079 stale proxy password leak — curl - - 2026-07-03
CVE-2026-8932 incomplete mTLS config matching in conn reuse — curl - - 2026-07-03
CVE-2026-8927 env-set cross-proxy Digest auth state leak — curl - - 2026-07-03
CVE-2026-8926 password leak with netrc and user in URL — curl - - 2026-07-03
CVE-2026-8925 SASL double-free — curl - - 2026-07-03
CVE-2026-8924 trailing dot domain super cookie — curl - - 2026-07-03
CVE-2026-8458 wrong reuse for different services — curl - - 2026-07-03
CVE-2026-8286 wrong STARTTLS connection reuse — curl - - 2026-07-03
CVE-2026-12064 proto-default skips SSH verification — curl - - 2026-07-03
CVE-2026-11856 cross-origin Digest auth state leak — curl - - 2026-07-03
CVE-2026-11586 WS Auto-PONG memory exhaustion — curl - - 2026-07-03
CVE-2026-11564 Native CA trust persist — curl - - 2026-07-03
CVE-2026-11352 QUIC zero-length UDP datagrams busy-loop — curl - - 2026-07-03
CVE-2026-10536 HTTP/2 stream-dependency tree UAF — curl - - 2026-07-03
CVE-2026-7168 cross-proxy Digest auth state leak — curl - - 2026-05-13
CVE-2026-7009 OCSP stapling bypass with Apple SecTrust — curl - - 2026-05-13
CVE-2026-6429 netrc credential leak with reused proxy connection — curl - - 2026-05-13
CVE-2026-6276 stale custom cookie host causes cookie leak — curl - - 2026-05-13
CVE-2026-6253 proxy credentials leak over redirect-to proxy — curl - - 2026-05-13
CVE-2026-5773 wrong reuse of SMB connection — curl - - 2026-05-13
CVE-2026-5545 wrong reuse of HTTP Negotiate connection — curl - - 2026-05-13
CVE-2026-4873 connection reuse ignores TLS requirement — curl - - 2026-05-13
CVE-2026-3805 use after free in SMB connection reuse — curl 9.1 - 2026-03-11
CVE-2026-3784 wrong proxy connection reuse with credentials — curl 7.5 - 2026-03-11
CVE-2026-3783 token leak with redirect and netrc — curl 6.5 - 2026-03-11
CVE-2026-1965 bad reuse of HTTP Negotiate connection — curl 7.7 - 2026-03-11

This page lists every published CVE security advisory associated with CURL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.