curl / Docs / Releases / curl CVEs

curl CVEs

If you find or suspect a security problem in curl or libcurl, please file a detailed report to us.

See also the Vulnerabilities Table to see what versions that are vulnerable to what flaws.

Published vulnerabilities for curl/libcurl

All | Medium+ | High+ | Critical

(The table below has been filtered to show Medium+ severity)

# S W C Vulnerability Published First Last Awarded
209
M
CVE-2026-19931: Negotiate ambient user conn reuse 2026-09-02 7.64.1 8.21.0
205
M
lib CVE-2026-11856: cross-origin Digest auth state leak 2026-06-24 7.10.6 8.20.0
196
M
lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
194
M
lib CVE-2026-8927: env-set cross-proxy Digest auth state leak 2026-06-24 7.12.0 8.20.0
192
M
C
CVE-2026-8925: SASL double-free 2026-06-24 8.15.0 8.20.0
188
M
lib CVE-2026-7168: cross-proxy Digest auth state leak 2026-04-29 7.12.0 8.19.0
187
M
CVE-2026-7009: OCSP stapling bypass with Apple SecTrust 2026-04-29 8.17.0 8.19.0
186
M
lib CVE-2026-6429: netrc credential leak with reused proxy connection 2026-04-29 7.14.0 8.19.0
184
M
CVE-2026-6253: proxy credentials leak over redirect-to proxy 2026-04-29 7.14.1 8.19.0
182
M
CVE-2026-5545: wrong reuse of HTTP Negotiate connection 2026-04-29 7.10.6 8.19.0
180
M
C
CVE-2026-3805: use after free in SMB connection reuse 2026-03-11 8.13.0 8.18.0
178
M
CVE-2026-3783: token leak with redirect and netrc 2026-03-11 7.33.0 8.18.0
177
M
CVE-2026-1965: bad reuse of HTTP Negotiate connection 2026-03-11 7.10.6 8.18.0
172
M
lib CVE-2025-14017: broken TLS options for threaded LDAPS 2026-01-07 7.17.0 8.17.0 2540 USD
171
M
CVE-2025-13034: No QUIC certificate pinning with GnuTLS 2026-01-07 8.8.0 8.17.0 2540 USD
166
M
CVE-2025-5025: No QUIC certificate pinning with wolfSSL 2025-05-28 8.5.0 8.13.0 2540 USD
165
M
CVE-2025-4947: QUIC certificate check skip with wolfSSL 2025-05-28 8.8.0 8.13.0 2540 USD
159
M
CVE-2024-8096: OCSP stapling bypass with GnuTLS 2024-09-11 7.41.0 8.9.1 2540 USD
156
M
C
CVE-2024-6197: freeing stack buffer in utf8asn1str 2024-07-24 8.6.0 8.8.0 2540 USD
155
M
CVE-2024-2466: TLS certificate check bypass with mbedTLS 2024-03-27 8.5.0 8.6.0 2540 USD
154
M
lib CVE-2024-2398: HTTP/2 push headers memory-leak 2024-03-27 7.44.0 8.6.0 2540 USD
149
M
CVE-2023-46218: cookie mixed case PSL bypass 2023-12-06 7.46.0 8.4.0 2540 USD
147
H
C
CVE-2023-38545: SOCKS5 heap buffer overflow 2023-10-11 7.69.0 8.3.0 4660 USD
146
M
CVE-2023-38039: HTTP headers eat all memory 2023-09-13 7.84.0 8.2.1 2540 USD
142
M
C
CVE-2023-28319: UAF in SSH sha256 fingerprint check 2023-05-17 7.81.0 8.0.1 2400 USD
138
M
CVE-2023-27535: FTP too eager connection reuse 2023-03-20 7.13.0 7.88.1 2400 USD
135
M
CVE-2023-23916: HTTP multi-header compression denial of service 2023-02-15 7.57.0 7.87.0 2400 USD
131
M
CVE-2022-43551: Another HSTS bypass via IDN 2022-12-21 7.77.0 7.86.0 2400 USD
130
M
CVE-2022-42916: HSTS bypass via IDN 2022-10-26 7.77.0 7.85.0 2400 USD
129
M
C
CVE-2022-42915: HTTP proxy double free 2022-10-26 7.77.0 7.85.0
127
M
lib CVE-2022-32221: POST following PUT confusion 2022-10-26 7.7 7.85.0 2400 USD
124
M
CVE-2022-32207: Non-preserved file permissions 2022-06-27 7.69.0 7.83.1 2400 USD
123
M
CVE-2022-32206: HTTP compression denial of service 2022-06-27 7.57.0 7.83.1 2400 USD
121
M
CVE-2022-30115: HSTS bypass via trailing dot 2022-05-11 7.82.0 7.83.0 2400 USD
120
M
CVE-2022-27782: TLS and SSH connection too eager reuse 2022-05-11 7.16.1 7.83.0 2400 USD
118
M
CVE-2022-27780: percent-encoded path separator in URL host 2022-05-11 7.80.0 7.83.0 2400 USD
117
M
CVE-2022-27779: cookie for trailing dot TLD 2022-05-11 7.82.0 7.83.0 2400 USD
116
M
tool CVE-2022-27778: curl removes wrong file on error 2022-05-11 7.83.0 7.83.0 2400 USD
113