curl / Docs / Releases / curl CVEs

curl CVEs

If you find or suspect a security problem in curl or libcurl, please file a detailed report to us.

See also the Vulnerabilities Table to see what versions that are vulnerable to what flaws.

Published vulnerabilities for curl/libcurl

All | Medium+ | High+ | Critical

(The table below shows vulnerabilities of all severity levels)

# S W C Vulnerability Published First Last Awarded
215
L
CVE-2026-82209: domain-scoped PSL domain cookie 2026-09-02 7.46.0 8.21.0
214
L
lib CVE-2026-82208: wolfSSL CA-cache hit overrides callback 2026-09-02 8.9.1 8.21.0
213
L
CVE-2026-80255: secure cookie attribute bypass with tab 2026-09-02 8.13.0 8.21.0
212
L
CVE-2026-80231: native CA store conn reuse 2026-09-02 7.71.0 8.21.0
211
L
CVE-2026-80230: OpenSSL pinning bypass 2026-09-02 7.45.0 8.21.0
210
L
C
CVE-2026-80229: OpenSSL provider use-after-free 2026-09-02 8.14.0 8.21.0
209
M
CVE-2026-19931: Negotiate ambient user conn reuse 2026-09-02 7.64.1 8.21.0
208
L
lib
C
CVE-2026-18924: HTTP/2 server push UAF 2026-09-02 7.44.0 8.21.0
207
L
CVE-2026-13608: OpenLDAP SASL authentication bypass 2026-09-02 7.82.0 8.21.0
206
L
tool CVE-2026-12064: proto-default skips SSH verification 2026-06-24 7.81.0 8.20.0
205
M
lib CVE-2026-11856: cross-origin Digest auth state leak 2026-06-24 7.10.6 8.20.0
204
L
CVE-2026-11586: WS Auto-PONG memory exhaustion 2026-06-24 8.16.0 8.20.0
203
L
lib CVE-2026-11564: Native CA trust persist 2026-06-24 8.17.0 8.20.0
202
L
CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop 2026-06-24 8.18.0 8.20.0
201
L
lib
C
CVE-2026-10536: HTTP/2 stream-dependency tree UAF 2026-06-24 7.88.0 8.20.0
200
L
lib CVE-2026-9547: SSH improper host validation 2026-06-24 7.69.0 8.20.0
199
L
lib CVE-2026-9546: sending old referer 2026-06-24 8.18.0 8.20.0
198
L
CVE-2026-9545: exposing HTTP/3 early data 2026-06-24 8.11.0 8.20.0
197
L
lib
C
CVE-2026-9080: UAF after pause in socket callback 2026-06-24 8.13.0 8.20.0
196
M
lib CVE-2026-9079: stale proxy password leak 2026-06-24 8.8.0 8.20.0
195
L
lib CVE-2026-8932: incomplete mTLS config matching in conn reuse 2026-06-24 7.7 8.20.0
194
M
lib CVE-2026-8927: env-set cross-proxy Digest auth state leak 2026-06-24 7.12.0 8.20.0
193
L
CVE-2026-8926: password leak with netrc and user in URL 2026-06-24