VendorsHaxxcurlall versions
Vulnerabilities

Haxx Curl

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

170CVEs
CVE-2014-0015
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Published 2014-02-02 · Modified
4.0EPSS 0.056
CVE-2014-2522
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
Published 2014-04-18 · Modified
4.0EPSS 0.026
CVE-2022-35252
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
Published 2022-09-23 · Modified
3.7EPSS 0.024
CVE-2024-2004
Usage of disabled protocol
Published 2024-03-27 · Analyzed
3.5EPSS 0.017
CVE-2024-11053
netrc and redirect credential leak
Published 2024-12-11 · Modified
3.4EPSS 0.013
CVE-2025-0167
netrc and default credential leak
Published 2025-02-05 · Analyzed
3.4EPSS 0.007
CVE-2020-19909
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks (or longer) before trying to recover from a transient error.
Published 2023-08-22 · Modified
3.3EPSS 0.004
CVE-2021-22898
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.
Published 2021-06-11 · Modified
3.1EPSS 0.045
CVE-2025-15224
libssh key passphrase bypass without agent set
Published 2026-01-08 · Modified
3.1EPSS 0.005
CVE-2017-7407
The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.
Published 2017-04-03 · Modified
2.4EPSS 0.006
← Prev5 / 5