CRITICAL9.8CVE-2026-10536A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPEND… from 0
from 0, < 7.74.0-1.3+deb11u10
from 0, < 7.74.0-1.3+deb11u10
CRITICAL9.8curl - security update
from 0, < 7.74.0-1.3+deb11u5
CRITICAL9.8curl - security update
from 0, < 7.74.0-1.3+deb11u5
CRITICAL9.8libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow.
from 0, < 7.64.0-1
CRITICAL9.8curl - security update
from 0, < 7.62.0-1
CRITICAL9.8curl - security update
from 0, < 7.38.0-4+deb8u12
CRITICAL9.8curl - security update
from 0, < 7.52.1-5+deb9u7
CRITICAL9.8The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled i…
from 0, < 7.51.0-1
CRITICAL9.8The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
from 0, < 7.51.0-1
CRITICAL9.8The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`.
from 0, < 7.51.0-1
CRITICAL9.8The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` m…
from 0, < 7.51.0-1
CRITICAL9.8curl - security update
from 0, < 7.58.0-1
CRITICAL9.8curl - security update
from 0, < 7.26.0-1+wheezy24
CRITICAL9.8curl - security update
from 0, < 7.38.0-4+deb8u9
CRITICAL9.8curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash…
from 0, < 7.57.0-1
CRITICAL9.8curl - security update
from 0, < 7.57.0-1
CRITICAL9.8curl - security update
from 0, < 7.38.0-4+deb8u8
CRITICAL9.8curl - security update
from 0, < 7.51.0-1
CRITICAL9.8curl - security update
from 0, < 7.26.0-1+wheezy16
CRITICAL9.1When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already free…
from 0, < 7.74.0-1.3+deb11u2
CRITICAL9.1libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers.
from 0, < 7.58.0-1
CRITICAL9.1curl - security update
from 0, < 7.56.1-1
CRITICAL9.1curl - security update
from 0, < 7.26.0-1+wheezy22
CRITICAL9.1curl - security update
from 0, < 7.38.0-4+deb8u7
HIGH8.8Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execut…
from 0, < 7.13.0-2
HIGH8.1A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--r…
from 0, < 7.83.1-1
HIGH8.1curl - security update
from 0, < 7.52.1-1
HIGH8.1curl - security update
from 0, < 7.26.0-1+wheezy18
HIGH8.1Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified oth…
from 0, < 7.50.1-1
HIGH7.8curl - security update
from 0, < 7.64.0-4
HIGH7.8curl - security update
from 0, < 7.38.0-4+deb8u15
HIGH7.5When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer a…
from 0
HIGH7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
from 0, < 8.14.1-2+deb13u4
HIGH7.5libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string.
from 0, < 8.9.0-1
HIGH7.5A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA…
from 0, < 7.88.1-10
HIGH7.5libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse…
from 0, < 7.74.0-1.3+deb11u2
HIGH7.5libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Du…
from 0, < 7.74.0-1.3+deb11u2
HIGH7.5curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP respo…
from 0, < 7.74.0-1
HIGH7.5curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
from 0, < 7.74.0-1
HIGH7.5curl - security update
from 0, < 7.72.0-1
HIGH7.5curl - security update
from 0, < 7.52.1-5+deb9u12
HIGH7.5libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP.
from 0, < 7.64.0-1
HIGH7.5curl - security update
from 0, < 7.64.0-1
HIGH7.5curl - security update
from 0, < 7.38.0-4+deb8u14
HIGH7.5curl - security update
from 0, < 7.52.1-5+deb9u9
HIGH7.5curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
from 0, < 7.10.7-1
HIGH7.5curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and…
from 0, < 7.51.0-1
HIGH7.5A flaw was found in curl before version 7.51.0.
from 0, < 7.51.0-1
HIGH7.5curl - security update
from 0, < 7.51.0-1
HIGH7.5curl - security update
from 0, < 7.26.0-1+wheezy17
HIGH7.5curl - security update
from 0, < 7.38.0-4+deb8u5
HIGH7.5The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit sho…
from 0, < 7.51.0-1
HIGH7.5curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, an…
from 0, < 7.51.0-1
HIGH7.5In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had change…
from 0, < 7.52.1-5
HIGH7.5curl - security update
from 0, < 7.56.1-1
HIGH7.5curl - security update
from 0, < 7.26.0-1+wheezy21
HIGH7.5curl - security update
from 0, < 7.51.0-1
HIGH7.5curl - security update
from 0, < 7.38.0-4+deb8u13
HIGH7.5curl - security update
from 0, < 7.26.0-1+wheezy15
HIGH7.5curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote atta…
from 0, < 7.50.1-1
HIGH7.5curl - security update
from 0, < 7.50.1-1
HIGH7.5curl - security update
from 0, < 7.26.0-1+wheezy14
HIGH7.5curl - security update
from 0, < 7.38.0-4+deb8u4
HIGH7.4When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may s…
from 0
HIGH7.3curl - security update
from 0, < 7.47.0-1
HIGH7.3curl - security update
from 0, < 7.38.0-4+deb8u3
HIGH7.0libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded…
from 0, < 8.12.0+git20250209.89ed161+ds-1
HIGH7.0The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at leas…
from 0, < 7.51.0-1
MEDIUM6.5curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials fo…
from 0
MEDIUM6.5libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.
from 0
MEDIUM6.5libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field.
from 0, < 7.74.0-1.3+deb11u13
MEDIUM6.5curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentiall…
from 0, < 7.74.0-1.3+deb11u2
MEDIUM6.5A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redire…
from 0, < 7.74.0-1.3+deb11u2
MEDIUM6.5curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificat…
from 0, < 7.52.1-3
MEDIUM6.5curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence o…
from 0, < 7.55.0-1
MEDIUM6.5curl - security update
from 0, < 7.55.0-1
MEDIUM6.5curl - security update
from 0, < 7.26.0-1+wheezy20
MEDIUM6.5curl - security update
from 0, < 7.38.0-4+deb8u6
MEDIUM6.3libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL.
from 0
MEDIUM5.9curl - security update
from 0, < 7.74.0-1.3+deb11u9
MEDIUM5.9curl - security update
from 0, < 7.64.0-4+deb10u7
MEDIUM5.9A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, s…
from 0
MEDIUM5.9A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles".
from 0, < 7.88.1-7
MEDIUM5.9An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connect…
from 0, < 7.74.0-1.3+deb11u8
MEDIUM5.9An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials be…
from 0, < 7.74.0-1.3+deb11u8
MEDIUM5.9A use after free vulnerability exists in curl <7.87.0.
from 0, < 7.74.0-1.3+deb11u5
MEDIUM5.9A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and pas…
from 0, < 7.51.0-1
MEDIUM5.5An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite th…
from 0, < 7.74.0-1.3+deb11u8
MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that to…
from 0
MEDIUM5.3When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could acci…
from 0, < 7.88.1-10+deb12u15
MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses…
from 0
MEDIUM5.3curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says.
from 0, < 7.88.1-10+deb12u15
MEDIUM5.3curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed.
from 0, < 8.6.0-1
MEDIUM5.3curl - security update
from 0, < 7.74.0-1.2
MEDIUM5.3curl - security update
from 0, < 7.52.1-5+deb9u14
MEDIUM5.3The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcur…
from 0, < 7.50.1-1
MEDIUM4.6URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without t…
from 0, < 8.14.1-2+deb13u2
MEDIUM4.3libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN.
from 0, < 8.9.0-1