Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CURL — Vulnerabilities & Security Advisories 74

Browse all 74 CVE security advisories affecting CURL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CURL is a widely utilized command-line tool and library for transferring data with URL syntax, supporting protocols like HTTP, HTTPS, and FTP. Its ubiquity in automation scripts and embedded systems makes it a frequent target for attackers seeking initial access or data exfiltration. Historically, vulnerabilities in the software have predominantly involved buffer overflows, integer overflows, and improper input validation, leading to potential remote code execution or denial-of-service conditions. While cross-site scripting is less relevant due to its non-browser nature, privilege escalation risks arise when executed with elevated permissions. Notable incidents include critical flaws allowing attackers to bypass security checks or execute arbitrary commands through crafted URLs. With 39 recorded CVEs, maintaining updated versions is essential to mitigate these persistent risks associated with its extensive protocol support and deep integration into global infrastructure.

Found 74 results / 74 Clear Filters
Top products by CURL: curl
CVE ID Title CVSS Severity Published
CVE-2026-6276 stale custom cookie host causes cookie leak — curl CWE-346 - - 2026-05-13
CVE-2026-6253 proxy credentials leak over redirect-to proxy — curl CWE-522 - - 2026-05-13
CVE-2026-5773 wrong reuse of SMB connection — curl CWE-488 - - 2026-05-13
CVE-2026-5545 wrong reuse of HTTP Negotiate connection — curl CWE-305 - - 2026-05-13
CVE-2026-4873 connection reuse ignores TLS requirement — curl CWE-319 - - 2026-05-13
CVE-2026-3805 use after free in SMB connection reuse — curl CWE-416 9.1 - 2026-03-11
CVE-2026-3784 wrong proxy connection reuse with credentials — curl CWE-305 7.5 - 2026-03-11
CVE-2026-3783 token leak with redirect and netrc — curl CWE-522 6.5 - 2026-03-11
CVE-2026-1965 bad reuse of HTTP Negotiate connection — curl CWE-305 7.7 - 2026-03-11
CVE-2025-11563 wcurl path traversal with percent-encoded slashes — curl 9.1AI Critical AI 2026-02-25
CVE-2025-15224 libssh key passphrase bypass without agent set — curl CWE-287 9.8 - 2026-01-08
CVE-2025-15079 libssh global known_hosts override — curl CWE-297 7.5 - 2026-01-08
CVE-2025-14819 OpenSSL partial chain store policy bypass — curl CWE-295 8.2 - 2026-01-08
CVE-2025-14524 bearer token leak on cross-protocol redirect — curl CWE-522 4.3 - 2026-01-08
CVE-2025-14017 broken TLS options for threaded LDAPS — curl CWE-567 4.3 - 2026-01-08
CVE-2025-13034 No QUIC certificate pinning with GnuTLS — curl CWE-295 7.5 - 2026-01-08
CVE-2025-10966 missing SFTP host verification with wolfSSH — curl CWE-322 7.4 - 2025-11-07
CVE-2025-10148 predictable WebSocket mask — curl CWE-340 7.1 - 2025-09-12
CVE-2025-9086 Out of bounds read for cookie path — curl CWE-125 8.1 - 2025-09-12
CVE-2025-5399 WebSocket endless loop — curl 7.5AI High AI 2025-06-07
CVE-2025-5025 No QUIC certificate pinning with wolfSSL — curl 6.5AI Medium AI 2025-05-28
CVE-2025-4947 QUIC certificate check skip with wolfSSL — curl 7.4AI High AI 2025-05-28
CVE-2025-0725 gzip integer overflow — curl 8.8 - 2025-02-05
CVE-2025-0665 eventfd double close — curl 7.1 - 2025-02-05
CVE-2025-0167 netrc and default credential leak — curl 5.9 - 2025-02-05
CVE-2024-11053 netrc and redirect credential leak — curl 6.5 - 2024-12-11
CVE-2024-9681 HSTS subdomain overwrites parent cache entry — curl 5.9AI Medium AI 2024-11-06
CVE-2024-8096 OCSP stapling bypass with GnuTLS — curl 7.5AI High AI 2024-09-11
CVE-2024-7264 ASN.1 date parser overread — curl 9.1AI Critical AI 2024-07-31
CVE-2024-6874 macidn punycode buffer overread — curl 9.1AI Critical AI 2024-07-24

This page lists every published CVE security advisory associated with CURL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.