VendorsHaxxcurlany version
Vulnerabilities

Haxx Curl any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

146CVEs
CVE-2025-14819
OpenSSL partial chain store policy bypass
Published 2026-01-08 · Modified
5.3EPSS 0.007
CVE-2025-14524
bearer token leak on cross-protocol redirect
Published 2026-01-08 · Modified
5.3EPSS 0.007
CVE-2026-7168
cross-proxy Digest auth state leak
Published 2026-05-13 · Modified
5.3EPSS 0.006
CVE-2025-15079
libssh global known_hosts override
Published 2026-01-08 · Modified
5.3EPSS 0.005
CVE-2026-6429
netrc credential leak with reused proxy connection
Published 2026-05-13 · Modified
5.3EPSS 0.005
CVE-2026-3783
token leak with redirect and netrc
Published 2026-03-11 · Modified
5.3EPSS 0.005
CVE-2025-10148
predictable WebSocket mask
Published 2025-09-12 · Modified
5.3EPSS 0.005
CVE-2026-7009
OCSP stapling bypass with Apple SecTrust
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2015-3153
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
Published 2015-05-01 · Modified
5.0EPSS 0.072
CVE-2014-3613
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
Published 2014-11-18 · Modified
5.0EPSS 0.071
CVE-2013-1944
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
Published 2013-04-29 · Modified
5.0EPSS 0.043
CVE-2014-3620
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
Published 2014-11-18 · Modified
5.0EPSS 0.042
CVE-2025-5025
No QUIC certificate pinning with wolfSSL
Published 2025-05-28 · Analyzed
4.8EPSS 0.003
CVE-2025-11563
wcurl path traversal with percent-encoded slashes
Published 2026-02-25 · Analyzed
4.6EPSS 0.004
CVE-2011-3389
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
Published 2011-09-06 · Modified
4.3EPSS 0.733
CVE-2022-32205
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this method.
Published 2022-07-07 · Modified
4.3EPSS 0.279
CVE-2019-5435
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
Published 2019-05-28 · Modified
4.3EPSS 0.047
CVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Published 2020-12-14 · Modified
4.3EPSS 0.039
CVE-2022-30115
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.
Published 2022-06-01 · Modified
4.3EPSS 0.013
CVE-2025-10966
missing SFTP host verification with wolfSSH
Published 2025-11-07 · Modified
4.3EPSS 0.004
CVE-2022-35252
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Published 2022-09-23 · Modified
3.7EPSS 0.024
CVE-2024-2004
Usage of disabled protocol
Published 2024-03-27 · Analyzed
3.5EPSS 0.017
CVE-2024-11053
netrc and redirect credential leak
Published 2024-12-11 · Modified
3.4EPSS 0.013
CVE-2025-0167
netrc and default credential leak
Published 2025-02-05 · Analyzed
3.4EPSS 0.007
CVE-2021-22898
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Published 2021-06-11 · Modified
3.1EPSS 0.045
CVE-2025-15224
libssh key passphrase bypass without agent set
Published 2026-01-08 · Modified
3.1EPSS 0.005
← Prev4 / 4