TOPCURL.md
July 18, 2026 · View on GitHub
Top reports from curl program at HackerOne:
- CVE-2021-22901: TLS session caching disaster to curl - 75 upvotes, $0
- HTTP/3 Stream Dependency Cycle Exploit to curl - 59 upvotes, $0
- CVE-2025-5399: WebSocket endless loop to curl - 57 upvotes, $0
- Use-After-Free in SMB connection reuse (req->path dangling pointer after needle destruction) to curl - 57 upvotes, $0
- CVE-2020-8177: curl overwrite local file with -J to curl - 55 upvotes, $0
- CVE-2023-38545: socks5 heap buffer overflow to curl - 54 upvotes, $0
- Memory Leak in libcurl via Location Header Handling (CWE-770) to curl - 54 upvotes, $0
- CVE-2025-5025: No QUIC certificate pinning with wolfSSL to curl - 54 upvotes, $0
- CVE-2024-7264: ASN.1 date parser overread to curl - 53 upvotes, $0
- Buffer overflow in strcpy to curl - 53 upvotes, $0
- CVE-2020-8286: Inferior OCSP verification to curl - 51 upvotes, $0
- CVE-2024-9681: HSTS subdomain overwrites parent cache entry to curl - 49 upvotes, $0
- Hackers Attack Curl Vulnerability Accessing Sensitive Information to curl - 48 upvotes, $0
- Integer Underflow in src/var.c to curl - 46 upvotes, $0
- Buffer Overflow Vulnerability in strcpy() Leading to Remote Code Execution to curl - 45 upvotes, $0
Curl_socketpair()fallback vulnerable to man-in-the-middle attack to curl - 45 upvotes, $0- MQTT Protocol Packet Injection via Unchecked CONNACK Remaining Length to curl - 45 upvotes, $0
- Negotiate connection reuse with wrong credentials when using CURLAUTH_ANY to curl - 45 upvotes, $0
- Security check up to curl - 44 upvotes, $0
- CVE-2025-4947: QUIC certificate check skip with wolfSSL to curl - 43 upvotes, $0
- CVE-2025-10966: missing SFTP host verification with wolfSSH to curl - 43 upvotes, $0
- wcurl Argument Injection via Unquoted Variable to curl - 43 upvotes, $0
- CRLF Injection in
--proxy-headerallows extra HTTP headers (CWE-93) to curl - 42 upvotes, $0 - mbedTLS private-key blob null-termination asymmetry in lib/vtls/mbedtls.c (mbed_load_privkey) to curl - 42 upvotes, $0
- curl --skip-existing has a TOCTOU race that lets a post-check symlink redirect the later download write to curl - 42 upvotes, $0
- Credential leak on redirect due to improper state clearing when parsing macdef in netrc.c to curl - 41 upvotes, $0
- Buffer Overflow Risk in Curl_inet_ntop and inet_ntop4 to curl - 39 upvotes, $0
- Negotiate Authentication Premature on Connection Reuse to curl - 39 upvotes, $0
- HTTP/3 paused transfer buffers incoming data without bound up to ~1 GiB to curl - 39 upvotes, $0
- Buffer Overflow Vulnerability in WebSocket Handling to curl - 38 upvotes, $0
- urlapi: off-by-one in custom scheme validation skips last character to curl - 38 upvotes, $0
- Bypassing Strict SSH Server Verification via Connection Pool Reuse in libcurl to curl - 37 upvotes, $0
- CVE-2026-7168: cross-proxy Digest auth state leak to curl - 37 upvotes, $0
- CVE-2024-8096: OCSP stapling bypass with GnuTLS to curl - 36 upvotes, $0
- CVE-2025-0167: netrc and default credential leak to curl - 36 upvotes, $0
- Sensitive information disclosure with malicious netrc file to curl - 36 upvotes, $0
- CVE-2025-9086: Out of bounds read for cookie path to curl - 36 upvotes, $0
- Integer Overflow in curl_multi_get_handles() Leading to Heap Buffer Overflow to curl - 36 upvotes, $0
- MQTT state machine confusion: PINGRESP/DISCONNECT with non-zero remaining_length dispatches to stale nextstate to curl - 36 upvotes, $0
- Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses scheme-blind comparator to curl - 35 upvotes, $0
- CVE-2024-6197: freeing stack buffer in utf8asn1str to curl - 34 upvotes, $0
- Unsanitized IPFS CID Allows SSRF Against Configured Gateway to curl - 34 upvotes, $0
- testing hackerone functions to curl - 34 upvotes, $0
- CVE-2024-2004: Usage of disabled protocol to curl - 33 upvotes, $0
- CVE-2024-11053: netrc + redirect credential leak to curl - 33 upvotes, $0
- on the implications of permitting procedural culling to curl - 33 upvotes, $0
- CVE-2026-3805: use after free in SMB connection reuse to curl - 33 upvotes, $0
- CVE-2026-7009: OCSP stapling bypass with Apple SecTrust to curl - 33 upvotes, $0
- WebSocket Fragmentation DoS on Curl Client to curl - 32 upvotes, $0
- Missing Security Headers to curl - 32 upvotes, $0
- Exposed .git/config File Leading to Potential Sensitive Information Disclosure to curl - 32 upvotes, $0
- Arbitrary File Read via file:// Protocol in cURL to curl - 31 upvotes, $0
- SSL options ISSUERCERT, EC_CURVES and CRLFILE silently ignored by non-OpenSSL backends to curl - 31 upvotes, $0
- CVE-2020-8284: trusting FTP PASV responses to curl - 30 upvotes, $0
- cookie is sent on redirect to curl - 30 upvotes, $0
- bypass of this Fixed #2437131 [ Inadequate Protocol Restriction Enforcement in curl ] to curl - 30 upvotes, $0
- Use-After-Free in OpenSSL Keylog Callback via SSL_get_ex_data() in libcurl to curl - 30 upvotes, $0
- Use After Free (that leads to arbitrary Write for some versions) to curl - 30 upvotes, $0
- libcurl: Host-Only Cookies Leak to Alternate IPv4 Forms to curl - 30 upvotes, $0
- CVE-2025-10148: predictable WebSocket mask to curl - 30 upvotes, $0
- OpenSSL backend: X509 peer certificate not freed in ossl_get_channel_binding causes per-request memory leak (DoS risk for long-lived clients) to curl - 30 upvotes, $0
- Apple SecTrust legacy path accepts untrusted certificates on pre-10.14 macOS/iOS when built with USE_APPLE_SECTRUST to curl - 30 upvotes, $0
- A quiet New Year wish for security researchers to curl - 30 upvotes, $0
- Cross‑origin cookies leak and injection risk when using a custom Host header to curl - 30 upvotes, $0
- CVE-2026-3784: wrong proxy connection reuse with credentials to curl - 30 upvotes, $0
- SMB READ_ANDX DataOffset not validated to curl - 30 upvotes, $0
- HTTP/1.1 Response Desynchronization via conflicting CL/TE headers in Proxy CONNECT to curl - 30 upvotes, $0
- lib/http2.c: SSL connections accept non-HTTP push schemes (incomplete fix for 2e8c922a) to curl - 30 upvotes, $0
- Schannel custom-CA path skips Extended Key Usage enforcement to curl - 30 upvotes, $0
- ("possible") UAF to curl - 29 upvotes, $0
- Heap‑based buffer overflow in curl -K <config_file> allows arbitrary write . to curl - 29 upvotes, $0
- Internal application wrapper or script using curl to curl - 29 upvotes, $0
- libcurl omits IPv6 zoneid from host identity and leaks credentials/cookies across scoped link-local realms to curl - 29 upvotes, $0
- MQTT CONNACK Packet Type Bypass leads to RCE via Malicious Broker to curl - 29 upvotes, $0
- CVE-2023-46218: cookie mixed case PSL bypass to curl - 28 upvotes, $0
- Memory Leak to curl - 28 upvotes, $0
- Integer Overflow in schannel.c TLS Data Transmission to curl - 28 upvotes, $0
- curl leaks destination IP via glibc getaddrinfo() UDP connect, bypassing SOCKS5/Tor to curl - 28 upvotes, $0
- Timing Attack Vulnerability in curl Digest Authentication via Non-Constant-Time String Comparison to curl - 28 upvotes, $0
- Out-of-bounds read in HTTP method handling causes undefined behavior and potential crash This is sharp, Gaurav. We’ve got a real memory-safety bug ins to curl - 28 upvotes, $0
- Cookie Max-Age Integer Overflow Vulnerability to curl - 28 upvotes, $0
- RTSP RTP Interleaved Parser Assertion Failure (Zero-Length RTP Payload) to curl - 28 upvotes, $0
- Curl_compareheader() fails to match multi-value HTTP headers to curl - 28 upvotes, $0
- SSH/SFTP connection reuse can bypass SSH key identity after ssh_config_matches removal to curl - 28 upvotes, $0
- Vulnerability Report: Buffer Overflow in Path Sanitization to curl - 28 upvotes, $0
- CVE-2023-46219: HSTS long file name clears contents to curl - 27 upvotes, $0
- Double Free Vulnerability in
libcurlCookie Management (cookie.c) to curl - 27 upvotes, $0 - Stack use-after-scope in HTTP/3 POST request processing via CURLOPT_POSTFIELDS to curl - 27 upvotes, $0
- SMTP Command Injection Vulnerabilities in curl to curl - 27 upvotes, $0
- AWS SigV4 Signature Disclosure via Verbose Logging in libcurl to curl - 27 upvotes, $0
- Heap-OOB read in urlapi
redirect_url()viaCURLU_GUESS_SCHEME+CURLU_NO_GUESS_SCHEMEflow to curl - 27 upvotes, $0 - CVE-2023-32001: fopen race condition to curl - 26 upvotes, $0
- NULL dereference when encoding DN of x509 certificate to curl - 26 upvotes, $0
- Use after free (read) in curl_multi_perform with DoH and Proxy options, and resolve timeouts to curl - 26 upvotes, $0
- Default Minimum TLS Version Set to TLS v1.0 (Cryptographic Weakness) to curl - 26 upvotes, $0
- Exposure of Private RSA Private Key in curl GitHub Repository to curl - 26 upvotes, $0
- Security Analysis Report: CURL Integer Overflow Vulnerability to curl - 26 upvotes, $0
- HackerOne to curl - 26 upvotes, $0
- Arbitrary free in curl's config file parsing. to curl - 26 upvotes, $0
- Unescaped username in SASL DIGEST-MD5 response allows injection to curl - 26 upvotes, $0
- HackerOne Vulnerability Report: libcurl SSL/TLS Identity Leakage via Insecure Connection Reuse to curl - 26 upvotes, $0
- CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine to curl - 25 upvotes, $0
- CVE-2024-6874: macidn punycode buffer overread to curl - 25 upvotes, $0
- Directory Traversal Vulnerability in cURL via Content-Disposition Header Processing to curl - 25 upvotes, $0
- CVE-2026-3783: token leak with redirect and netrc to curl - 25 upvotes, $0
- NULL Pointer Dereference (DoS) in libcurl SFTP QUOTE command parsing due to missing return statement to curl - 25 upvotes, $0
- HSTS accepted from HTTP origin behind HTTPS proxy to curl - 25 upvotes, $0
- CVE-2019-5435: An integer overflow found in /lib/urlapi.c to curl - 24 upvotes, $0
- CVE-2025-0665: eventfd double close to curl - 24 upvotes, $0
- curl ASSERTs when accessing an LDAP URL to curl - 24 upvotes, $0
- Vulnerability Report: Public Exposure of Security Audit File to curl - 24 upvotes, $0
- Heap-buffer-overflow (Out-of-Bounds Read) in DoH hostname encoding to curl - 24 upvotes, $0
- HTTP/3 Protocol Smuggling and Header Injection via CRLF in QPACK value conversion to curl - 24 upvotes, $0
- SSTI leads to Command injection to curl - 24 upvotes, $0
- HTTP/2 server push accepts a non-authoritative :scheme=https over cleartext h2c, enabling HTTPS cache-key poisoning to curl - 24 upvotes, $0
- CVE-2026-6276: stale custom cookie host causes cookie leak to curl - 24 upvotes, $0
- CVE-2026-6253: proxy credentials leak over redirect-to proxy to curl - 24 upvotes, $0
- curl GnuTLS backend accepts a clientAuth-only certificate for HTTPS server authentication to curl - 24 upvotes, $0
- CVE-2024-0853: OCSP verification bypass with TLS session reuse to curl - 23 upvotes, $0
- Exploitable Format String Vulnerability in curl_mfprintf Function to curl - 23 upvotes, $0
- HTTP Request Smuggling Vulnerability Analysis - cURL Security Report to curl - 23 upvotes, $0
- Curl parse_connect_to_string Heap-Overread Leading to Denial of Service via CURLOPT_CONNECT_TO to curl - 23 upvotes, $0
- TOCTOU Race Condition in HTTP/2 Connection Reuse Leads to Certificate Validation Bypass to curl - 23 upvotes, $0
- [SFTP] TOCTOU Race Condition in Upload Resume Logic Leads to Arbitrary File Append to curl - 23 upvotes, $0
- Bearer Token Leaked to Attacker via .netrc Despite CVE-2026-3783 Fix to curl - 23 upvotes, $0
- Use-After-Free race condition in url_move_hostname() via shared connection pool to curl - 23 upvotes, $0
- Data race in Curl_dnscache_add_negative() corrupts shared DNS cache — heap corruption and double-free when using CURLOPT_SHARE with CURL_LOCK_DATA_DNS to curl - 23 upvotes, $0
- libcurl: Integer truncation in curl_easy_ssls_import() causes TLS sessions to never expire to curl - 23 upvotes, $0
- Argument Injection via curl Short-Flag Grouping to curl - 23 upvotes, $0
- wcurl treats some URL operands after -- as curl options to curl - 23 upvotes, $0
- Inconsistent URL Parsing in curl Leading to Potential SSRF and Access Control Bypass to curl - 22 upvotes, $0
- Hi Hacker to curl - 22 upvotes, $0
- Able to bypass HSTS using trailing dot to curl - 22 upvotes, $0
- libcurl stale CURLOPT_AUTOREFERER leaks a previous request URL to a different origin on a reused easy handle to curl - 22 upvotes, $0
- CVE-2026-5545: wrong reuse of HTTP Negotiate connection to curl - 22 upvotes, $0
- Kerberos/SPNEGO Connection Reuse Vulnerability to curl - 22 upvotes, $0
- Connection reuse ignores haproxyprotocol and HAPROXY_CLIENT_IP settings, allowing PROXY context to persist across transfers to curl - 22 upvotes, $0
- GnuTLS OCSP stapling accepts unrelated SingleResponse (no cert-ID binding) to curl - 22 upvotes, $0
- CVE-2020-8169: Partial password leak over DNS on HTTP redirect to curl - 21 upvotes, $0
- Buffer overflow and affected url:-https://github.com/curl/curl/blob/master/docs/examples/hsts-preload.c to curl - 21 upvotes, $0
- Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl to curl - 21 upvotes, $0
- HTTP Proxy Bypass via
CURLOPT_CUSTOMREQUESTVerb Tunneling to curl - 21 upvotes, $0 - CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling to curl - 21 upvotes, $0
- Disk Space Exhaustion leading to a Denial of Service (DoS) to curl - 21 upvotes, $0
- OpenSSL HTTP/3 bogus CURLINFO_TLS_SSL_PTR to curl - 21 upvotes, $0
- Incorrect Parsing of IPv6 Zone ID in curl to curl - 21 upvotes, $0
- Unbounded memory consumption via compressed HTTP responses (gzip/brotli/zstd) to curl - 21 upvotes, $0
- Cookie Replacement Use-After-Free Vulnerability to curl - 21 upvotes, $0
- Potential Resource Leak in tool_parsecfg.c at line 279 during fileerror to curl - 21 upvotes, $0
- heap-use-after-free in state.referer when CURLOPT_REFERER replaced or cleared after perform to curl - 21 upvotes, $0
- CVE-2023-28319: UAF in SSH sha256 fingerprint check to curl - 20 upvotes, $0
- HTTP/2 PUSH_PROMISE DoS to curl - 20 upvotes, $0
- Incorrect Type Conversion in interpreting IPv4-mapped IPv6 addresses and below
curlresults in indeterminate SSRF vulnerabilities. to curl - 20 upvotes, $0 - Memory leak of ftp (with proxy reuse) to curl - 20 upvotes, $0
- Uncontrolled File Write/Arbitrary File Creation to curl - 20 upvotes, $0
- GnuTLS CURLINFO_TLS_SESSION / CURLINFO_TLS_SSL_PTR type confusion to curl - 20 upvotes, $0
- Cookie exposure due to unexpected file permission change to curl - 20 upvotes, $0
- Title: Use-After-Free in cURL Test Suite via Improper Cleanup of Global Handle to curl - 20 upvotes, $0
- Functional Regression in Digest Authentication: Failure to handle optional spaces and escaped quotes to curl - 20 upvotes, $0
- Protocol Smuggling / CRLF Injection via Gopher Protocol allows Arbitrary Command Injection to curl - 20 upvotes, $0
- HTTP/2 and HTTP/3 Header Injection in curl to curl - 20 upvotes, $0
- Incomplete Suppression of Transfer-Encoding: chunked Header in HTTP/2 After Redirect From HTTP/1.1 to curl - 20 upvotes, $0
- CVE-2022-27776: Auth/cookie leak on redirect to curl - 19 upvotes, $0
- When curl uses Schannel as TLS backend, it fails to enforce TLS 1.3 cipher suite selections correctly to curl - 19 upvotes, $0
- Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE Mismatch to curl - 19 upvotes, $0
- Insecure WebSocket Usage in curl Documentation and Examples (CWE-319: Cleartext Transmission of Sensitive Information) to curl - 19 upvotes, $0
- Account/Repository Takeover via Abandoned GitHub Username in curl's href_extractor.c to curl - 19 upvotes, $0
- ## Title Heap Use-After-Free Vulnerability in
curlLeading to Potential Code Execution to curl - 19 upvotes, $0 - Confirmed Security Misconfigurations on curl.se (BREACH, Missing Security Headers, ETag Info Disclosure) to curl - 19 upvotes, $0
- File URL UNC Path Access (Windows SSRF) to curl - 19 upvotes, $0
- PROTOCOL-LEVEL: Persistent UDP Amplification and Cache Poisoning via Alt-Svc Logic Flaw to curl - 19 upvotes, $0
- Use after free in hyperfifo example to curl - 19 upvotes, $0
- CVE-2026-6429: netrc credential leak with reused proxy connection to curl - 19 upvotes, $0
- CRLF Injection via Custom HTTP Headers to curl - 19 upvotes, $0
- Multiple Unsafe strcpy() Function Calls Leading to Potential Buffer Overflow Vulnerabilities in cURL 8.16.1-DEV to curl - 18 upvotes, $0
- Stack Buffer Overflow in cURL Cookie Parsing Leads to RCE to curl - 18 upvotes, $0
- SMTP Command Injection Vulnerability in libcurl 8.16.0 via RFC 3461 Suffix to curl - 18 upvotes, $0
- Integer Overflow to Heap Overflow in DoH Response Handling to curl - 18 upvotes, $0
- curl built with GnuTLS backend defaults to weak crypto parameters to curl - 18 upvotes, $0
- Path Traversal Bypass in file:// URLs Due to Incomplete URL-Encoded Path Normalization to curl - 18 upvotes, $0
- Proxy-Authorization header is leaked to origin server after redirect from proxied to direct connection to curl - 18 upvotes, $0
- Path Traversal in curl file:// Protocol Handler Allows Unauthorized File Access to curl - 18 upvotes, $0
- CVE-2025-15079: libssh global knownhost override to curl - 18 upvotes, $0
- LM Challenge-Response Hash Always Sent in SMB Authentication to curl - 18 upvotes, $0
- CURLOPT_UNRESTRICTED_AUTH Dangerous Default Documentation Gap to curl - 18 upvotes, $0
- Cookie attribute TAB injection regression in Set-Cookie parsing to curl - 18 upvotes, $0
- libcurl 8.20.0 incomplete fix for CVE-2026-7168: changing only CURLOPT_PROXYPORT leaks stale Proxy Digest auth to a different proxy to curl - 18 upvotes, $0
- CVE-2024-2466: TLS certificate check bypass with mbedTLS to curl - 17 upvotes, $0
- CVE-2025-0725: gzip integer overflow to curl - 17 upvotes, $0
- int overflow in krb5_read_data() leads to (possible) massive
recv()write to curl - 17 upvotes, $0 - Race condition on global
gss_contextduring SOCKS5 GSS-API negotiation in libcurl to curl - 17 upvotes, $0 - Use of Deprecated strcpy() with User-Controlled Environment Variable in Memory Debug Initialization to curl - 17 upvotes, $0
- Infinite loop issue in the state machine of the curl project to curl - 17 upvotes, $0
- Certificate Hostname Validation Bypass via Leading Dot in Hostname to curl - 17 upvotes, $0
- Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 17 upvotes, $0
- CVE-2025-14524: bearer token leak on cross-protocol redirect to curl - 17 upvotes, $0
- libcurl: Improper Authentication State Management on Cross-Protocol Redirects to curl - 17 upvotes, $0
- In curl's SASL OAUTHBEARER authentication, including the SOH character (0x01) in the username corrupts the message structure. to curl - 17 upvotes, $0
- Connection Reuse Ignores OAuth Bearer Token Mismatch to curl - 17 upvotes, $0
- Unbounded GZIP Decompression Leading to Event-Loop Starvation to curl - 17 upvotes, $0
- Digest Auth State Leak on Cross-Origin Redirect via Netrc - Username and Password Hash Sent to Wrong Host to curl - 17 upvotes, $0
- SSL session-cache peer key omits signature_algorithms: strict-sigalg handle silently resumes a permissive sibling's session to curl - 17 upvotes, $0
- libcurl: HTTP/1.x bare LF byte in response header value enables cookie jar pollution and POST body/credential exfiltration via redirect — RC=0, curl 8 to curl - 17 upvotes, $0
- Duplicate chunked Transfer-Encoding lets a malicious origin smuggle a response across reused HTTP proxy connections to curl - 17 upvotes, $0
- mbedTLS / wolfSSL / rustls backends silently skip hostname verification when CURLOPT_SSL_VERIFYPEER=0 to curl - 17 upvotes, $0
- CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c to curl - 16 upvotes, $0
- CVE-2022-43552: HTTP Proxy deny use-after-free to curl - 16 upvotes, $0
- CVE-2023-23916: HTTP multi-header compression denial of service to curl - 16 upvotes, $0
- Speculative Execution Side-Channel in
curlto curl - 16 upvotes, $0 - Use-after-free when POST body buffer is freed before transfer to curl - 16 upvotes, $0
- Buffer Overflow in WebSocket Handshake (lib/ws.c:1287) to curl - 16 upvotes, $0
- libcurl FTP path normalization flaw allows decoded %2e%2e → CWD .. and directory escape (Path Traversal, CWE-22) to curl - 16 upvotes, $0
- HAProxy Connection Reuse leads to IP Spoofing and mTLS Context Smuggling to curl - 16 upvotes, $0
- Cross‑Layer State Confusion in libcurl: Credential & Key‑Material Persistence Across Redirect / Connection Reuse Boundaries to curl - 16 upvotes, $0
- Telnet Suboption Buffer Pointer Underflow in lib/telnet.c leads to Out-of-Bounds Read to curl - 16 upvotes, $0
- SMTP CRLF Injection & Protocol Desynchronization in libcurl to curl - 16 upvotes, $0
- Missing server identity policy enforcement in SSH connection reuse allows host key verification bypass via pool poisoning to curl - 16 upvotes, $0
- Mentioned unites are at the same time .Then we have to increase the bounty. to curl - 16 upvotes, $0
- UAF read in mev_pollset_diff() trace path after curl_easy_pause() in socket callback to curl - 16 upvotes, $0
- Format string vulnerability, curl_msnprintf() function to curl - 15 upvotes, $0
- Use after free (or assert triggered) with failed allocations in openssl to curl - 15 upvotes, $0
- Unsafe Global IFS Modification in OS400 Shell Script Enables Command Injection and Parsing Flaws (CWE-78/CWE-20) to curl - 15 upvotes, $0
- Incorrect sizeof() in Rustls Backend Memory Allocation to curl - 15 upvotes, $0
- Path Traversal in file:// protocol allows Arbitrary File Read to curl - 15 upvotes, $0
- Buffer Overflow in cURL Internal printf Function to curl - 15 upvotes, $0
- HTTP/2 PUSH_PROMISE header loss on OOM bypasses scheme validation (regression of 2e8c922a89) to curl - 15 upvotes, $0
- Improper enforcement of CURLOPT_SOCKS5_AUTH due to missing reuse key validation in libcurl to curl - 15 upvotes, $0
- no_proxy IDN mismatch: Unicode hostnames bypass proxy exclusion list to curl - 15 upvotes, $0
- Integer Overflow/Signedness Mismatch in Printf Precision for HTTP/2 Trailer Headers to curl - 15 upvotes, $0
- CURLOPT_PROXY_CAINFO_BLOB silently activates native CA store on Apple builds to curl - 15 upvotes, $0
- TLS conn reuse and session cache ignore fsslctx callback and ssl_config_data flags ( incomplete fix variant of 7541ae569 ) to curl - 15 upvotes, $0
- CVE-2021-22897: schannel cipher selection surprise to curl - 14 upvotes, $0
- CVE-2021-22945: UAF and double-free in MQTT sending to curl - 14 upvotes, $0
- HTTP/2 CONTINUATION Flood Vulnerability to curl - 14 upvotes, $0
- Stack-based Buffer Overflow in TELNET NEW_ENV Option Handling to curl - 14 upvotes, $0
- Elevation of Privileges (EoP) vulnerabilities related to the some easy_options on Windows to curl - 14 upvotes, $0
- curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments to curl - 14 upvotes, $0
- curl --continue-at confusion to curl - 14 upvotes, $0
- access notes without permission to curl - 14 upvotes, $0
- Exposure of Hard-coded Private Keys and Credentials in curl Source Repository (CWE-321) to curl - 14 upvotes, $0
- Unsafe use of strcpy in Curl_ldap_err2string (packages/OS400/os400sys.c) — stack-buffer-overflow (PoC + ASan) to curl - 14 upvotes, $0
- Heap Buffer Overflow in TFTP to curl - 14 upvotes, $0
- MQTT Protocol Violation & Integer Overflow in libcurl to curl - 14 upvotes, $0
- IMAP Protocol Desynchronization and Response Smuggling via Naive Literal Parsing to curl - 14 upvotes, $0
- CVE-2022-35252: control code in cookie denial of service to curl - 13 upvotes, $0
- Authorization Header Leak via --location-trusted in Curl to curl - 13 upvotes, $0
- Title: Remote Code Execution (RCE) via Arbitrary Library Loading in
--engineoption to curl - 13 upvotes, $0 - Memory leak in Curl_auth_create_ntlm_type3_message to curl - 13 upvotes, $0
- Denial of Service (DoS) vulnerability in dedotdotify() URL path normalization to curl - 13 upvotes, $0
- Alt-Svc bypasses credential leak protection (CVE-2018-1000007) to curl - 13 upvotes, $0
- CVE-2025-15224: libssh key passphrase bypass without agent set to curl - 13 upvotes, $0
- Function
do_pubkey()can have out-of-bound read issue to curl - 13 upvotes, $0 - Security Vulnerability Report: Protocol Injection via Programmatic Options to curl - 13 upvotes, $0
- libcurl reuses a learned RTSP Session header across different hosts on the same easy handle, enabling cross-host session leak and replay to curl - 13 upvotes, $0
- CVE-2026-4873: connection reuse ignores TLS requirement to curl - 13 upvotes, $0
- cookie: case-insensitive path comparison in replace_existing() allows cookie eviction across distinct paths to curl - 13 upvotes, $0
- OpenSSL TLS 1.2 session resumption accepts expired server certificates in libcurl to curl - 13 upvotes, $0
- Secure cookies leaked to HTTP origins through HTTPS forwarding proxy to curl - 13 upvotes, $0
- CVE-2023-27537: HSTS double-free to curl - 12 upvotes, $0
- CVE-2024-2398: HTTP/2 push headers memory-leak to curl - 12 upvotes, $0
- Unicode-to-ASCII conversion on Windows can lead to argument injection and more to curl - 12 upvotes, $0
- OS Command Injection in scripts/firefox-db2pem.sh via untrusted certificate nicknames to curl - 12 upvotes, $0
- Missing enforcement of SFTP quote syntax can lead to operation on wrong object to curl - 12 upvotes, $0
- CURLX_SET_BINMODE(NULL) can call fileno(NULL) and cause undefined behavior / crash to curl - 12 upvotes, $0
- runs javascript on powershell when it shouldnt to curl - 12 upvotes, $0
- Stack Buffer Overflow in cURL wolfSSL Backend (lib/vtls/wolfssl.c) to curl - 12 upvotes, $0
- A logic error in detect_proxy caused truncation of environment variable names for long protocol schemes. to curl - 12 upvotes, $0
- Security hardening: missing integer overflow check in curl_load_library() to curl - 12 upvotes, $0
- CVE-2026-5773: wrong reuse of SMB connection to curl - 12 upvotes, $0
- libssh SFTP initialization ignores CURLOPT_TIMEOUT, hangs indefinitely to curl - 12 upvotes, $0
- CURLOPT_HSTS_CTRL disables shared HSTS without share guard — use-after-free and double-free to curl - 12 upvotes, $0
- Shared HSTS cache accessed without lock to curl - 12 upvotes, $0
- CURLOPT_PROXY_CRLFILE / CURLOPT_PROXY_ISSUERCERT / CURLOPT_PROXY_ISSUERCERT_BLOB silently ignored on backends that don't support them to curl - 12 upvotes, $0
- curl External-Controlled Filename in
--url @fileLeads to Arbitrary File Overwrite to curl - 12 upvotes, $0 - CURLOPT_HAPROXY_CLIENT_IP lacks input validation, enabling HAProxy PROXY protocol injection to curl - 12 upvotes, $0
- Use-after-free in
mev_forget_socketwhencurl_easy_pause()is called from aCURL_POLL_REMOVEsocket callback (incomplete fix of CVE-2026-9080) to curl - 12 upvotes, $0 - CVE-2020-8231: Connect-only connections can use the wrong connection to curl - 11 upvotes, $0
- CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize to curl - 11 upvotes, $0
- CVE-2022-27778: curl removes wrong file on error to curl - 11 upvotes, $0
- CVE-2022-32208: FTP-KRB bad message verification to curl - 11 upvotes, $0
- CVE-2024-2379: QUIC certificate check bypass with wolfSSL to curl - 11 upvotes, $0
- curl allows SSH connection even if host is not in known_hosts to curl - 11 upvotes, $0
- Failure to strip Proxy-Authorization header on change in origin to curl - 11 upvotes, $0
- Stack Buffer Overflow in curl's OpenSSL Provider Handling to curl - 11 upvotes, $0
- Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet to curl - 11 upvotes, $0
- Information Disclosure at : https://curl.se/.mailmap to curl - 11 upvotes, $0
- SMTP CRLF Command Injection in CURLOPT_MAIL_FROM and CURLOPT_MAIL_RCPT to curl - 11 upvotes, $0
- Silent TLS Trust Model Hijacking via
CURL_CA_BUNDLEEnvironment Variable Leads to MITM to curl - 11 upvotes, $0 - Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash to curl - 11 upvotes, $0
- Public-suffix cookie injection when libpsl is disabled to curl - 11 upvotes, $0
- Integer Overflow in
curl_easy_escape()may lead to heap buffer overflow and stack memory disclosure on 32-bit platforms to curl - 11 upvotes, $0 - Curl Telnet Handler Buffer Overflow to curl - 11 upvotes, $0
- TLS peer-verification bypass via mid-transfer ssl_config mutation to curl - 11 upvotes, $0
- DNS domain search list followed for extant domain missing A or AAAA records to curl - 11 upvotes, $0
- curl-ipv4-percent-normalization-SSRF to curl - 11 upvotes, $0
- verify-release rebuilds from the tarball under verification, enabling pre-check command execution and false OK for a malicious curl release tarball to curl - 11 upvotes, $0
- heap-use-after-free in curl_easy_cleanup() called from callback to curl - 11 upvotes, $0
- SMB access smuggling via FILE URL on Windows to curl - 10 upvotes, $0
- CVE-2021-22946: Protocol downgrade required TLS bypassed to curl - 10 upvotes, $0
- Heap Buffer Overflow in libcurl curl_slist_append via Unterminated String to curl - 10 upvotes, $0
- [High] MITM via Insecure CA Path Handling in cURL (--capath, CURLOPT_CAPATH) (CWE-494: Download of Code Without Integrity Check) to curl - 10 upvotes, $0
- curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things to curl - 10 upvotes, $0
- arbitrary file read via
file://path traversal with--path-as-isto curl - 10 upvotes, $0 - Git repository found to curl - 10 upvotes, $0
- information disclosure to curl - 10 upvotes, $0
- Path Traversal in SFTP QUOTE command leads to Arbitrary File Write and potential RCE to curl - 10 upvotes, $0
- curl’s persistence files inherit world-readable/writable perms from umask, leaking and tampering with cookies/HSTS/Alt-Svc caches to curl - 10 upvotes, $0
- Logical Flaw in curl_url_set Leads to Inconsistent Query Parameter Encoding to curl - 10 upvotes, $0
- libcurl WebSocket handshake accepts any Sec-WebSocket-Accept to curl - 10 upvotes, $0
- MQTT: Missing upper bound on incoming Remaining Length allows server-controlled long wait to curl - 10 upvotes, $0
- Directory listing vulnerability is disclosing names and emails, widespread (thousands of records, publicly accessible without auth) to curl - 10 upvotes, $0
- FTP entrypath accepts 0xFF (Telnet IAC) through incomplete ISCNTRL filter, sent on wire via CWD on connection reuse to curl - 10 upvotes, $0
- Trailing-dot IPv4 URL bypasses IP-address guard, allows wildcard DNS SAN match to curl - 10 upvotes, $0
- curl cross-origin HTTPS redirect reuses TLS client certificate for unintended second-origin mTLS authentication to curl - 10 upvotes, $0
- SOCKS5 no-auth accepted despite username/password-only authentication to curl - 10 upvotes, $0
- Trailing-Dot Hostname in Redirect Silently Strips Client Certificate and Auth Credentials to curl - 10 upvotes, $0
- CVE-2022-27780: percent-encoded path separator in URL host to curl - 9 upvotes, $0
- Cache purge requests are not authenticated to curl - 9 upvotes, $0
- Memory leak from doh_write_cb to curl - 9 upvotes, $0
- curl_easy_header runs at O(N) or worse and can be abused to use minute(s) of CPU time to curl - 9 upvotes, $0
- Heap buffer overflow vulnerability in conncache.c: incorrect use of pointer arrays resulting in out-of-bounds memory writes. to curl - 9 upvotes, $0
- Disclosure of email addresses to curl - 9 upvotes, $0
- Vulnerability Report: Local File Disclosure via file:// Protocol in cURL to curl - 9 upvotes, $0
- Use of Deprecated strcpy() with Fixed-Size Buffers in Progress Time Formatting to curl - 9 upvotes, $0
- libcurl MQTT PUBLISH length overflow (heap overflow) to curl - 9 upvotes, $0
- Arbitrary Configuration File Inclusion: via External Control of File Name or Path to curl - 9 upvotes, $0
- Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 9 upvotes, $0
- WebSocket Logic Error: Control Frame (PING/PONG) Starvation causes Connection Drop (DoS) during large transfers to curl - 9 upvotes, $0
- CRLF Injection in Gopher Protocol (
lib/gopher.c) to curl - 9 upvotes, $0 - HTTP Request Smuggling and SSRF via CRLF Injection in Curl_add_custom_headers to curl - 9 upvotes, $0
- CRLF Injection in HAProxy PROXY Protocol via CURLOPT_HAPROXY_CLIENT_IP allows IP spoofing and protocol injection to curl - 9 upvotes, $0
- ignoring 'options' when doing connection reuse to curl - 9 upvotes, $0
- # SCURLOPT_SSH_KNOWNHOSTS and host fingerprint pins are silently bypassed when an SSH connection is reused from the connection pool to curl - 9 upvotes, $0
- HSTS multi-trailing-dot bypass-ish: possible incomplete fix for CVE-2022-30115 to curl - 9 upvotes, $0
- RTSP Digest auth state leaks across origins on reused libcurl easy handle to curl - 9 upvotes, $0
- Arbitrary File Read via Unsanitized curl Usage Results in Sensitive File Exposure to curl - 8 upvotes, $0
- Free of uninitialized pointer in doh_decode_rdata_name() to curl - 8 upvotes, $0
- Path Traversal Vulnerability in curl via Unsanitized IPFS_PATH Environment Variable to curl - 8 upvotes, $0
- Buffer Overflow in curl's Rustls Backend to curl - 8 upvotes, $0
- Double free caused by mqtt_doing() to curl - 8 upvotes, $0
- Potential XSS vector in curl via unsanitized URL parameter handling to curl - 8 upvotes, $0
- Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink() to curl - 8 upvotes, $0
- SOCKS5 Heap Buffer Overflow via Malicious HTTP Redirect with Oversized Hostname to curl - 8 upvotes, $0
- libcurl MQTT
CURLOPT_POSTFIELDSIZE_LARGEoverflow leads to immediate DoS to curl - 8 upvotes, $0 - SMTP CRLF Injection in curl/libcurl via MAIL FROM/RCPT TO parameters to curl - 8 upvotes, $0
- Command Injection - CRITICISM to curl - 8 upvotes, $0
- Hash exposed in public repository to curl - 8 upvotes, $0
- Malicious server forces .curlrc creation via curl -OJ leading to local file exfiltration to curl - 8 upvotes, $0
- Off-by-One Buffer Overflow in SMB Path Handler to curl - 8 upvotes, $0
- Terminal Output Not Great to curl - 8 upvotes, $0
- Curl Alt-Svc Parser Stack Buffer Overflow to curl - 8 upvotes, $0
- Heap Overflow in cURL AmigaOS Socket Implementation to curl - 8 upvotes, $0
- Heap Buffer Over-read in lib/http2.c (on_header) handling PUSH_PROMISE frames to curl - 8 upvotes, $0
- Stack Buffer Overflow in mprintf.c formatting function (fallback path) to curl - 8 upvotes, $0
- State Isolation Failure in Multiplexed Connections (Shared Auth Context) to curl - 8 upvotes, $0
- Use-After-Free in curl_easy_nextheader when reusing header handle across requests to curl - 8 upvotes, $0
- Gopher Protocol Command Injection (SSRF Smuggling) to curl - 8 upvotes, $0
- Digest Authentication Header Injection to curl - 8 upvotes, $0
- Use-after-free in
curl_easy_ssls_export()during callback re-entrancy to curl - 8 upvotes, $0 - rustls backend silently ignores CURLOPT_CRLFILE when native CA store is active to curl - 8 upvotes, $0
- lib/ldap.c follows attacker-controlled LDAP referrals and binds to a second server; WinLDAP builds leak current logon credentials (confirmed on Window to curl - 8 upvotes, $0
- CVE-2021-22890: TLS 1.3 session ticket proxy host mixup to curl - 7 upvotes, $0
- CVE-2021-22898: TELNET stack contents disclosure to curl - 7 upvotes, $0
- CVE-2021-22947: STARTTLS protocol injection via MITM to curl - 7 upvotes, $0
- CVE-2022-27774: Credential leak on redirect to curl - 7 upvotes, $0
- CVE-2022-27775: Bad local IPv6 connection reuse to curl - 7 upvotes, $0
- CVE-2022-30115: HSTS bypass via trailing dot to curl - 7 upvotes, $0
- CVE-2022-35260: .netrc parser out-of-bounds access to curl - 7 upvotes, $0
- CVE-2022-42915: HTTP proxy double-free to curl - 7 upvotes, $0
- CVE-2022-43551: Another HSTS bypass via IDN to curl - 7 upvotes, $0
- curl file writing susceptible to symlink attacks to curl - 7 upvotes, $0
- CVE-2023-23915: HSTS amnesia with --parallel to curl - 7 upvotes, $0
- Incorrect Encoding Conversion in hostname results in indeterminate SSRF vulnerabilities to curl - 7 upvotes, $0
- Improper Restriction of Authentication Attempts in cURL to curl - 7 upvotes, $0
- [High] Arbitrary File Write via Path Traversal in cURL CLI (
-o,--output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) to curl - 7 upvotes, $0 - Buffer over-read,, Missing NUL termination in addvariable() causes undefined behavior to curl - 7 upvotes, $0
- Certificate Pinning Bypass with wolfSSL backend over HTTP/3 to curl - 7 upvotes, $0
- inconsistently Rejection Logic in file:// URLs with Authority to curl - 7 upvotes, $0
- Integer-underflow leads to heap over-read in TFTP implementation to curl - 7 upvotes, $0
- Heap-buffer-overflow in
Curl_ssl_push_certinfo_len()— sole bounds check isDEBUGASSERTto curl - 7 upvotes, $0 - HTTP/2 proxy CONNECT tunnel unbounded 1xx chain (missing Curl_bump_headersize cap in cf-h2-proxy.c) to curl - 7 upvotes, $0
- TLS verifyhost bypass in rustls, mbedTLS, and wolfSSL when verifypeer=0 to curl - 7 upvotes, $0
- TFTP upload ignores --continue-at / CURLOPT_RESUME_FROM and leaks skipped local file prefix to curl - 7 upvotes, $0
- curl/libcurl vulnerable to TLS truncation attacks to curl - 7 upvotes, $0
- CVE-2026-12064: proto-default skips SSH verification to curl - 7 upvotes, $0
- ssh_config_matches is dead code: unauthorized SSH key reuse to curl - 7 upvotes, $0
- setopt(VERIFYPEER) from callback bypasses TLS verify on connection reuse to curl - 7 upvotes, $0
- Github wikis are editable by anyone #Githubwikistakeover to curl - 6 upvotes, $0
- CVE-2019-5481: krb5: double-free in read_data() after realloc() fail to curl - 6 upvotes, $0
- SSRF via maliciously crafted URL due to host confusion to curl - 6 upvotes, $0
- --libcurl code injection via trigraphs to curl - 6 upvotes, $0
- CVE-2022-22576: OAUTH2 bearer bypass in connection re-use to curl - 6 upvotes, $0
- CVE-2022-27782: TLS and SSH connection too eager reuse to curl - 6 upvotes, $0
- CVE-2022-32207: Unpreserved file permissions to curl - 6 upvotes, $0
- CVE-2023-23914: curl HSTS ignored on multiple requests to curl - 6 upvotes, $0
- CVE-2023-28320: siglongjmp race condition to curl - 6 upvotes, $0
- Denial of Service in curl Request - HTTP headers eat all memory to curl - 6 upvotes, $0
- -H with space prefix leads to previous header injection when used with --proxy to curl - 6 upvotes, $0
- netrc crlf injection to curl - 6 upvotes, $0
- SMTP Protocol Injection via CRLF in CURLOPT_MAIL_FROM leading to Email Spoofing to curl - 6 upvotes, $0
- CVE-2026-11564: Native CA trust persist to curl - 6 upvotes, $0
- Active Mixed Content over HTTPS to curl - 5 upvotes, $0
- CVE-2021-22876: Automatic referer leaks credentials to curl - 5 upvotes, $0
- CVE-2021-22922: Wrong content via metalink not discarded to curl - 5 upvotes, $0
- CVE-2021-22926: CURLOPT_SSLCERT mixup with Secure Transport to curl - 5 upvotes, $0
- CVE-2021-22924: Bad connection reuse due to flawed path name checks to curl - 5 upvotes, $0
- Remote memory disclosure vulnerability in libcurl on 64 Bit Windows to curl - 5 upvotes, $0
- CVE-2022-27779: cookie for trailing dot TLD to curl - 5 upvotes, $0
- Credential leak on redirect to curl - 5 upvotes, $0
- CVE-2022-27781: CERTINFO never-ending busy-loop to curl - 5 upvotes, $0
- TLS Cipher Misconfiguration in HTTP/3/QUIC Support to curl - 5 upvotes, $0
- curl mishandles
%0c%0bsequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection to curl - 5 upvotes, $0 - Double free in tool_ssls_load() to curl - 5 upvotes, $0
- CRLF Injection / Protocol Smuggling in libcurl via CURLOPT_USERNAME (IMAP) to curl - 5 upvotes, $0
- CRLF Injection in HTTP header values allows arbitrary header injection to curl - 5 upvotes, $0
- Heap Out-of-Bounds Read in lib/http2.c via Malformed PUSH_PROMISE Headers to curl - 5 upvotes, $0
- integer Overflow in MQTT Protocol Handling Allows Bypassing Message Size Limit to curl - 5 upvotes, $0
- SMTP Command Injection via CRLF in libcurl MAIL_FROM / MAIL_RCPT (lib/smtp.c) to curl - 5 upvotes, $0
- NULL pointer dereference in libcurl URL API redirect_url() with CURLU_DEFAULT_SCHEME to curl - 5 upvotes, $0
- Low priority HSTS bypass in curl_easy_duphandle() to curl - 5 upvotes, $0
- Use-after-free in
curl_easy_duphandle()with HTTP/2 stream-dependency tree to curl - 5 upvotes, $0 - libcurl 8.20.0 ignores HTTP Digest domain protection space and preemptively leaks Digest auth outside the declared scope to curl - 5 upvotes, $0
- CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop to curl - 5 upvotes, $0
- HTTPS proxy connection reuse lets one easy handle inherit another handle's mTLS-authenticated proxy session to curl - 5 upvotes, $0
- Signed integer overflow in tool_progress_cb() to curl - 4 upvotes, $0
- Invalid write (or double free) triggers curl command line tool crash to curl - 4 upvotes, $0
- Integer overflows in tool_operate.c at line 1541 to curl - 4 upvotes, $0
- CVE-2021-22923: Metalink download sends credentials to curl - 4 upvotes, $0
- CURLOPT_SSH_HOST_PUBLIC_KEY_MD5 bypass if string not 32 chars to curl - 4 upvotes, $0
- Memory leak in CURLOPT_XOAUTH2_BEARER to curl - 4 upvotes, $0
- error parse uri path in curl to curl - 4 upvotes, $0
- CVE-2022-32206: HTTP compression denial of service to curl - 4 upvotes, $0
- CVE-2022-32205: Set-Cookie denial of service to curl - 4 upvotes, $0
- libssh backend CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 validation bypass to curl - 4 upvotes, $0
- CVE-2023-27533: Telnet option IAC injection to curl - 4 upvotes, $0
- CVE-2023-27535: FTP too eager connection reuse to curl - 4 upvotes, $0
- CVE-2023-27536: GSS delegation too eager connection re-use to curl - 4 upvotes, $0
- CVE-2023-27538: SSH connection too eager reuse still to curl - 4 upvotes, $0
- OS Command Injection (subprocess Module Usage) to curl - 4 upvotes, $0
- Heap buffer overflow in Curl_ipv4_resolve_r due to incorrect buffer alignment and size calculation on AmigaOS to curl - 4 upvotes, $0
- MQTT: unsigned integer underflow bypasses MAX_MQTT_MESSAGE_SIZE check to curl - 4 upvotes, $0
- Stack exhaustion in MIME multipart reading with deeply nested subparts to curl - 4 upvotes, $0
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF to curl - 4 upvotes, $0
- CVE-2026-11586: WS Auto-PONG memory exhaustion to curl - 4 upvotes, $0
- curl overwrites local file with -J option if file non-readable, but file writable. to curl - 3 upvotes, $0
- CVE-2020-8285: FTP wildcard stack overflow to curl - 3 upvotes, $0
- Abusing URL Parsers by long schema name to curl - 3 upvotes, $0
- Poll loop/hang on incomplete HTTP header to curl - 3 upvotes, $0
- Integer overflow in the source code tool_cb_prg.c to curl - 3 upvotes, $0
- CVE-2021-22925: TELNET stack contents disclosure again to curl - 3 upvotes, $0
- Denial of Service vulnerability in curl when parsing MQTT server response to curl - 3 upvotes, $0
- Credential leak when use two url to curl - 3 upvotes, $0
- CVE-2022-32221: POST following PUT confusion to curl - 3 upvotes, $0
- CVE-2023-27534: SFTP path ~ resolving discrepancy to curl - 3 upvotes, $0
- CVE-2023-28322: more POST-after-PUT confusion to curl - 3 upvotes, $0
- Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations to curl - 3 upvotes, $0
- CURLOPT_COOKIE leaked to cross-origin redirect target — CURLOPT_UNRESTRICTED_AUTH bypass for the STRING_COOKIE path to curl - 3 upvotes, $0
- CURLSHOPT_UNSHARE race can cause UAF in shared SSL session cache during HTTPS transfer to curl - 3 upvotes, $0
- Heap Buffer Overflow (READ of size 1) in ourWriteOut to curl - 2 upvotes, $0
- Libcurl ocasionally sends HTTPS traffic to port 443 rather than specified port 8080 to curl - 2 upvotes, $0
- Integer overlow in "header_append" function to curl - 2 upvotes, $0
- curl on Windows can be forced to execute code via OpenSSL environment variables to curl - 2 upvotes, $0
- Proxy-Authorization header carried to a new host on a redirect to curl - 2 upvotes, $0
- Binary output bypass to curl - 2 upvotes, $0
- CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 comparison disaster to curl - 2 upvotes, $0
- Certificate authentication re-use on redirect to curl - 2 upvotes, $0
- Cookie injection from non-secure context to curl - 2 upvotes, $0
- Heap overflow via HTTP/2 PUSH_PROMISE to curl - 2 upvotes, $0
- CVE-2022-42916: HSTS bypass via IDN to curl - 2 upvotes, $0
- CVE-2023-28321: IDN wildcard match to curl - 2 upvotes, $0
- Proxy CONNECT response poisoning via authentication retry in cf-h1-proxy.c (libcurl) to curl - 2 upvotes, $0
- curl/libcurl 8.20.0 NOPROXY bypass via uppercase-hex IPv4 aliases leaks off-proxy Basic credentials to the configured proxy to curl - 2 upvotes, $0
- CVE-2026-9545: exposing HTTP/3 early data to curl - 2 upvotes, $0
- CVE-2026-8932: incomplete mTLS config matching in conn reuse to curl - 2 upvotes, $0
- CVE-2026-9080: UAF after pause in socket callback to curl - 2 upvotes, $0
- CVE-2026-9079: stale proxy password leak to curl - 2 upvotes, $0
- CVE-2026-9546: sending old referer to curl - 2 upvotes, $0
- Insecure Frame (External) to curl - 1 upvotes, $0
- Parallel upload hangs curl if upload file not found to curl - 1 upvotes, $0
- libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823 to curl - 1 upvotes, $0
- Race condition with CURL_LOCK_DATA_CONNECT can cause connections to be used at the same time to curl - 1 upvotes, $0
- Division by zero if terminal width is 2 to curl - 1 upvotes, $0
- Unexpected access to process open files via file:///proc/self/fd/n to curl - 1 upvotes, $0
- use after free in cookie.c to curl - 1 upvotes, $0
- Potential invocation of qsort on uninitialized memory during cookie save to curl - 1 upvotes, $0
- Resource leak when using a normal site as DOH server to curl - 1 upvotes, $0
- Buffer write overflow when forming dns over http request to curl - 1 upvotes, $0
- Integer overflow at line 1603 in the src/operator.c file to curl - 1 upvotes, $0
- huge COLUMNS causes progress-bar to buffer overflow to curl - 1 upvotes, $0
- Inadequate Cryptographic Key Size and Insecure Cryptographic Mode. File Name :- curl_ntlm_core.c to curl - 1 upvotes, $0
- Occasional use-after-free in multi_done() libcurl-7.81.0 to curl - 1 upvotes, $0
- Use of Unsafe function || Strcpy to curl - 1 upvotes, $0
- curl proceeds with unsafe connections when -K file can't be read to curl - 1 upvotes, $0
- KRB-FTP: Security level downgrade to curl - 1 upvotes, $0
- curl "globbing" can lead to denial of service attacks to curl - 1 upvotes, $0
- SMTP connection reuse ignores --ssl-reqd / CURLOPT_USE_SSL and reuses a clear-text STARTTLS session on current master to curl - 1 upvotes, $0
- PRE_PROXY change leaks stale Proxy Digest state across proxy-chain boundary to curl - 1 upvotes, $0
- CVE-2026-11856: cross-origin Digest auth state leak to curl - 1 upvotes, $0
- CVE-2026-8458: wrong reuse for different services to curl - 1 upvotes, $0
- CVE-2026-8926: password leak with netrc and user in URL to curl - 1 upvotes, $0
- CVE-2026-8925: SASL double-free to curl - 1 upvotes, $0
- CVE-2026-8927: env-set cross-proxy Digest auth state leak to curl - 1 upvotes, $0
- CVE-2026-8286: wrong STARTTLS connection reuse to curl - 1 upvotes, $0
- CVE-2026-9547: SSH improper host validation to curl - 1 upvotes, $0
- libcurl upload read callbacks miss recursive API guard, allowing prohibited multi API reentry and ASAN-confirmed UAF to curl - 1 upvotes, $0
- Port and service scanning on localhost due to improper URL validation. to curl - 0 upvotes, $0
- Data race conditions reported by helgrind when performing parallel DNS queries in libcurl to curl - 0 upvotes, $0
- Only OpenSSL handles a CRL when passed in via CApath to curl - 0 upvotes, $0
- curl successfully matches IP address literal in URL against IP address literal in certificate Common Name to curl - 0 upvotes, $0
- Curl_auth_create_plain_message integer overflow leads to heap buffer overflow to curl - 0 upvotes, $0
- curl still vulnerable to SMB access smuggling via FILE URL on Windows to curl - 0 upvotes, $0
- Incorrect IPv6 literal parsing leads to validated connection to unexpected https server. to curl - 0 upvotes, $0
- Double-free of
trailers_buf' onCurl_http_compile_trailers()` failure to curl - 0 upvotes, $0 - match to curl - 0 upvotes, $0
- Integer overflows in unescape_word() to curl - 0 upvotes, $0
- CVE-2026-8924: trailing dot domain super cookie to curl - 0 upvotes, $0