TOPCURL.md

July 18, 2026 · View on GitHub

Top reports from curl program at HackerOne:

  1. CVE-2021-22901: TLS session caching disaster to curl - 75 upvotes, $0
  2. HTTP/3 Stream Dependency Cycle Exploit to curl - 59 upvotes, $0
  3. CVE-2025-5399: WebSocket endless loop to curl - 57 upvotes, $0
  4. Use-After-Free in SMB connection reuse (req->path dangling pointer after needle destruction) to curl - 57 upvotes, $0
  5. CVE-2020-8177: curl overwrite local file with -J to curl - 55 upvotes, $0
  6. CVE-2023-38545: socks5 heap buffer overflow to curl - 54 upvotes, $0
  7. Memory Leak in libcurl via Location Header Handling (CWE-770) to curl - 54 upvotes, $0
  8. CVE-2025-5025: No QUIC certificate pinning with wolfSSL to curl - 54 upvotes, $0
  9. CVE-2024-7264: ASN.1 date parser overread to curl - 53 upvotes, $0
  10. Buffer overflow in strcpy to curl - 53 upvotes, $0
  11. CVE-2020-8286: Inferior OCSP verification to curl - 51 upvotes, $0
  12. CVE-2024-9681: HSTS subdomain overwrites parent cache entry to curl - 49 upvotes, $0
  13. Hackers Attack Curl Vulnerability Accessing Sensitive Information to curl - 48 upvotes, $0
  14. Integer Underflow in src/var.c to curl - 46 upvotes, $0
  15. Buffer Overflow Vulnerability in strcpy() Leading to Remote Code Execution to curl - 45 upvotes, $0
  16. Curl_socketpair() fallback vulnerable to man-in-the-middle attack to curl - 45 upvotes, $0
  17. MQTT Protocol Packet Injection via Unchecked CONNACK Remaining Length to curl - 45 upvotes, $0
  18. Negotiate connection reuse with wrong credentials when using CURLAUTH_ANY to curl - 45 upvotes, $0
  19. Security check up to curl - 44 upvotes, $0
  20. CVE-2025-4947: QUIC certificate check skip with wolfSSL to curl - 43 upvotes, $0
  21. CVE-2025-10966: missing SFTP host verification with wolfSSH to curl - 43 upvotes, $0
  22. wcurl Argument Injection via Unquoted Variable to curl - 43 upvotes, $0
  23. CRLF Injection in --proxy-header allows extra HTTP headers (CWE-93) to curl - 42 upvotes, $0
  24. mbedTLS private-key blob null-termination asymmetry in lib/vtls/mbedtls.c (mbed_load_privkey) to curl - 42 upvotes, $0
  25. curl --skip-existing has a TOCTOU race that lets a post-check symlink redirect the later download write to curl - 42 upvotes, $0
  26. Credential leak on redirect due to improper state clearing when parsing macdef in netrc.c to curl - 41 upvotes, $0
  27. Buffer Overflow Risk in Curl_inet_ntop and inet_ntop4 to curl - 39 upvotes, $0
  28. Negotiate Authentication Premature on Connection Reuse to curl - 39 upvotes, $0
  29. HTTP/3 paused transfer buffers incoming data without bound up to ~1 GiB to curl - 39 upvotes, $0
  30. Buffer Overflow Vulnerability in WebSocket Handling to curl - 38 upvotes, $0
  31. urlapi: off-by-one in custom scheme validation skips last character to curl - 38 upvotes, $0
  32. Bypassing Strict SSH Server Verification via Connection Pool Reuse in libcurl to curl - 37 upvotes, $0
  33. CVE-2026-7168: cross-proxy Digest auth state leak to curl - 37 upvotes, $0
  34. CVE-2024-8096: OCSP stapling bypass with GnuTLS to curl - 36 upvotes, $0
  35. CVE-2025-0167: netrc and default credential leak to curl - 36 upvotes, $0
  36. Sensitive information disclosure with malicious netrc file to curl - 36 upvotes, $0
  37. CVE-2025-9086: Out of bounds read for cookie path to curl - 36 upvotes, $0
  38. Integer Overflow in curl_multi_get_handles() Leading to Heap Buffer Overflow to curl - 36 upvotes, $0
  39. MQTT state machine confusion: PINGRESP/DISCONNECT with non-zero remaining_length dispatches to stale nextstate to curl - 36 upvotes, $0
  40. Credentials forwarded to HTTP after HTTPS→HTTP same-port redirect — url_set_data_creds uses scheme-blind comparator to curl - 35 upvotes, $0
  41. CVE-2024-6197: freeing stack buffer in utf8asn1str to curl - 34 upvotes, $0
  42. Unsanitized IPFS CID Allows SSRF Against Configured Gateway to curl - 34 upvotes, $0
  43. testing hackerone functions to curl - 34 upvotes, $0
  44. CVE-2024-2004: Usage of disabled protocol to curl - 33 upvotes, $0
  45. CVE-2024-11053: netrc + redirect credential leak to curl - 33 upvotes, $0
  46. on the implications of permitting procedural culling to curl - 33 upvotes, $0
  47. CVE-2026-3805: use after free in SMB connection reuse to curl - 33 upvotes, $0
  48. CVE-2026-7009: OCSP stapling bypass with Apple SecTrust to curl - 33 upvotes, $0
  49. WebSocket Fragmentation DoS on Curl Client to curl - 32 upvotes, $0
  50. Missing Security Headers to curl - 32 upvotes, $0
  51. Exposed .git/config File Leading to Potential Sensitive Information Disclosure to curl - 32 upvotes, $0
  52. Arbitrary File Read via file:// Protocol in cURL to curl - 31 upvotes, $0
  53. SSL options ISSUERCERT, EC_CURVES and CRLFILE silently ignored by non-OpenSSL backends to curl - 31 upvotes, $0
  54. CVE-2020-8284: trusting FTP PASV responses to curl - 30 upvotes, $0
  55. cookie is sent on redirect to curl - 30 upvotes, $0
  56. bypass of this Fixed #2437131 [ Inadequate Protocol Restriction Enforcement in curl ] to curl - 30 upvotes, $0
  57. Use-After-Free in OpenSSL Keylog Callback via SSL_get_ex_data() in libcurl to curl - 30 upvotes, $0
  58. Use After Free (that leads to arbitrary Write for some versions) to curl - 30 upvotes, $0
  59. libcurl: Host-Only Cookies Leak to Alternate IPv4 Forms to curl - 30 upvotes, $0
  60. CVE-2025-10148: predictable WebSocket mask to curl - 30 upvotes, $0
  61. OpenSSL backend: X509 peer certificate not freed in ossl_get_channel_binding causes per-request memory leak (DoS risk for long-lived clients) to curl - 30 upvotes, $0
  62. Apple SecTrust legacy path accepts untrusted certificates on pre-10.14 macOS/iOS when built with USE_APPLE_SECTRUST to curl - 30 upvotes, $0
  63. A quiet New Year wish for security researchers to curl - 30 upvotes, $0
  64. Cross‑origin cookies leak and injection risk when using a custom Host header to curl - 30 upvotes, $0
  65. CVE-2026-3784: wrong proxy connection reuse with credentials to curl - 30 upvotes, $0
  66. SMB READ_ANDX DataOffset not validated to curl - 30 upvotes, $0
  67. HTTP/1.1 Response Desynchronization via conflicting CL/TE headers in Proxy CONNECT to curl - 30 upvotes, $0
  68. lib/http2.c: SSL connections accept non-HTTP push schemes (incomplete fix for 2e8c922a) to curl - 30 upvotes, $0
  69. Schannel custom-CA path skips Extended Key Usage enforcement to curl - 30 upvotes, $0
  70. ("possible") UAF to curl - 29 upvotes, $0
  71. Heap‑based buffer overflow in curl -K <config_file> allows arbitrary write . to curl - 29 upvotes, $0
  72. Internal application wrapper or script using curl to curl - 29 upvotes, $0
  73. libcurl omits IPv6 zoneid from host identity and leaks credentials/cookies across scoped link-local realms to curl - 29 upvotes, $0
  74. MQTT CONNACK Packet Type Bypass leads to RCE via Malicious Broker to curl - 29 upvotes, $0
  75. CVE-2023-46218: cookie mixed case PSL bypass to curl - 28 upvotes, $0
  76. Memory Leak to curl - 28 upvotes, $0
  77. Integer Overflow in schannel.c TLS Data Transmission to curl - 28 upvotes, $0
  78. curl leaks destination IP via glibc getaddrinfo() UDP connect, bypassing SOCKS5/Tor to curl - 28 upvotes, $0
  79. Timing Attack Vulnerability in curl Digest Authentication via Non-Constant-Time String Comparison to curl - 28 upvotes, $0
  80. Out-of-bounds read in HTTP method handling causes undefined behavior and potential crash This is sharp, Gaurav. We’ve got a real memory-safety bug ins to curl - 28 upvotes, $0
  81. Cookie Max-Age Integer Overflow Vulnerability to curl - 28 upvotes, $0
  82. RTSP RTP Interleaved Parser Assertion Failure (Zero-Length RTP Payload) to curl - 28 upvotes, $0
  83. Curl_compareheader() fails to match multi-value HTTP headers to curl - 28 upvotes, $0
  84. SSH/SFTP connection reuse can bypass SSH key identity after ssh_config_matches removal to curl - 28 upvotes, $0
  85. Vulnerability Report: Buffer Overflow in Path Sanitization to curl - 28 upvotes, $0
  86. CVE-2023-46219: HSTS long file name clears contents to curl - 27 upvotes, $0
  87. Double Free Vulnerability in libcurl Cookie Management (cookie.c) to curl - 27 upvotes, $0
  88. Stack use-after-scope in HTTP/3 POST request processing via CURLOPT_POSTFIELDS to curl - 27 upvotes, $0
  89. SMTP Command Injection Vulnerabilities in curl to curl - 27 upvotes, $0
  90. AWS SigV4 Signature Disclosure via Verbose Logging in libcurl to curl - 27 upvotes, $0
  91. Heap-OOB read in urlapi redirect_url() via CURLU_GUESS_SCHEME + CURLU_NO_GUESS_SCHEME flow to curl - 27 upvotes, $0
  92. CVE-2023-32001: fopen race condition to curl - 26 upvotes, $0
  93. NULL dereference when encoding DN of x509 certificate to curl - 26 upvotes, $0
  94. Use after free (read) in curl_multi_perform with DoH and Proxy options, and resolve timeouts to curl - 26 upvotes, $0
  95. Default Minimum TLS Version Set to TLS v1.0 (Cryptographic Weakness) to curl - 26 upvotes, $0
  96. Exposure of Private RSA Private Key in curl GitHub Repository to curl - 26 upvotes, $0
  97. Security Analysis Report: CURL Integer Overflow Vulnerability to curl - 26 upvotes, $0
  98. HackerOne to curl - 26 upvotes, $0
  99. Arbitrary free in curl's config file parsing. to curl - 26 upvotes, $0
  100. Unescaped username in SASL DIGEST-MD5 response allows injection to curl - 26 upvotes, $0
  101. HackerOne Vulnerability Report: libcurl SSL/TLS Identity Leakage via Insecure Connection Reuse to curl - 26 upvotes, $0
  102. CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine to curl - 25 upvotes, $0
  103. CVE-2024-6874: macidn punycode buffer overread to curl - 25 upvotes, $0
  104. Directory Traversal Vulnerability in cURL via Content-Disposition Header Processing to curl - 25 upvotes, $0
  105. CVE-2026-3783: token leak with redirect and netrc to curl - 25 upvotes, $0
  106. NULL Pointer Dereference (DoS) in libcurl SFTP QUOTE command parsing due to missing return statement to curl - 25 upvotes, $0
  107. HSTS accepted from HTTP origin behind HTTPS proxy to curl - 25 upvotes, $0
  108. CVE-2019-5435: An integer overflow found in /lib/urlapi.c to curl - 24 upvotes, $0
  109. CVE-2025-0665: eventfd double close to curl - 24 upvotes, $0
  110. curl ASSERTs when accessing an LDAP URL to curl - 24 upvotes, $0
  111. Vulnerability Report: Public Exposure of Security Audit File to curl - 24 upvotes, $0
  112. Heap-buffer-overflow (Out-of-Bounds Read) in DoH hostname encoding to curl - 24 upvotes, $0
  113. HTTP/3 Protocol Smuggling and Header Injection via CRLF in QPACK value conversion to curl - 24 upvotes, $0
  114. SSTI leads to Command injection to curl - 24 upvotes, $0
  115. HTTP/2 server push accepts a non-authoritative :scheme=https over cleartext h2c, enabling HTTPS cache-key poisoning to curl - 24 upvotes, $0
  116. CVE-2026-6276: stale custom cookie host causes cookie leak to curl - 24 upvotes, $0
  117. CVE-2026-6253: proxy credentials leak over redirect-to proxy to curl - 24 upvotes, $0
  118. curl GnuTLS backend accepts a clientAuth-only certificate for HTTPS server authentication to curl - 24 upvotes, $0
  119. CVE-2024-0853: OCSP verification bypass with TLS session reuse to curl - 23 upvotes, $0
  120. Exploitable Format String Vulnerability in curl_mfprintf Function to curl - 23 upvotes, $0
  121. HTTP Request Smuggling Vulnerability Analysis - cURL Security Report to curl - 23 upvotes, $0
  122. Curl parse_connect_to_string Heap-Overread Leading to Denial of Service via CURLOPT_CONNECT_TO to curl - 23 upvotes, $0
  123. TOCTOU Race Condition in HTTP/2 Connection Reuse Leads to Certificate Validation Bypass to curl - 23 upvotes, $0
  124. [SFTP] TOCTOU Race Condition in Upload Resume Logic Leads to Arbitrary File Append to curl - 23 upvotes, $0
  125. Bearer Token Leaked to Attacker via .netrc Despite CVE-2026-3783 Fix to curl - 23 upvotes, $0
  126. Use-After-Free race condition in url_move_hostname() via shared connection pool to curl - 23 upvotes, $0
  127. Data race in Curl_dnscache_add_negative() corrupts shared DNS cache — heap corruption and double-free when using CURLOPT_SHARE with CURL_LOCK_DATA_DNS to curl - 23 upvotes, $0
  128. libcurl: Integer truncation in curl_easy_ssls_import() causes TLS sessions to never expire to curl - 23 upvotes, $0
  129. Argument Injection via curl Short-Flag Grouping to curl - 23 upvotes, $0
  130. wcurl treats some URL operands after -- as curl options to curl - 23 upvotes, $0
  131. Inconsistent URL Parsing in curl Leading to Potential SSRF and Access Control Bypass to curl - 22 upvotes, $0
  132. Hi Hacker to curl - 22 upvotes, $0
  133. Able to bypass HSTS using trailing dot to curl - 22 upvotes, $0
  134. libcurl stale CURLOPT_AUTOREFERER leaks a previous request URL to a different origin on a reused easy handle to curl - 22 upvotes, $0
  135. CVE-2026-5545: wrong reuse of HTTP Negotiate connection to curl - 22 upvotes, $0
  136. Kerberos/SPNEGO Connection Reuse Vulnerability to curl - 22 upvotes, $0
  137. Connection reuse ignores haproxyprotocol and HAPROXY_CLIENT_IP settings, allowing PROXY context to persist across transfers to curl - 22 upvotes, $0
  138. GnuTLS OCSP stapling accepts unrelated SingleResponse (no cert-ID binding) to curl - 22 upvotes, $0
  139. CVE-2020-8169: Partial password leak over DNS on HTTP redirect to curl - 21 upvotes, $0
  140. Buffer overflow and affected url:-https://github.com/curl/curl/blob/master/docs/examples/hsts-preload.c to curl - 21 upvotes, $0
  141. Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl to curl - 21 upvotes, $0
  142. HTTP Proxy Bypass via CURLOPT_CUSTOMREQUEST Verb Tunneling to curl - 21 upvotes, $0
  143. CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling to curl - 21 upvotes, $0
  144. Disk Space Exhaustion leading to a Denial of Service (DoS) to curl - 21 upvotes, $0
  145. OpenSSL HTTP/3 bogus CURLINFO_TLS_SSL_PTR to curl - 21 upvotes, $0
  146. Incorrect Parsing of IPv6 Zone ID in curl to curl - 21 upvotes, $0
  147. Unbounded memory consumption via compressed HTTP responses (gzip/brotli/zstd) to curl - 21 upvotes, $0
  148. Cookie Replacement Use-After-Free Vulnerability to curl - 21 upvotes, $0
  149. Potential Resource Leak in tool_parsecfg.c at line 279 during fileerror to curl - 21 upvotes, $0
  150. heap-use-after-free in state.referer when CURLOPT_REFERER replaced or cleared after perform to curl - 21 upvotes, $0
  151. CVE-2023-28319: UAF in SSH sha256 fingerprint check to curl - 20 upvotes, $0
  152. HTTP/2 PUSH_PROMISE DoS to curl - 20 upvotes, $0
  153. Incorrect Type Conversion in interpreting IPv4-mapped IPv6 addresses and below curl results in indeterminate SSRF vulnerabilities. to curl - 20 upvotes, $0
  154. Memory leak of ftp (with proxy reuse) to curl - 20 upvotes, $0
  155. Uncontrolled File Write/Arbitrary File Creation to curl - 20 upvotes, $0
  156. GnuTLS CURLINFO_TLS_SESSION / CURLINFO_TLS_SSL_PTR type confusion to curl - 20 upvotes, $0
  157. Cookie exposure due to unexpected file permission change to curl - 20 upvotes, $0
  158. Title: Use-After-Free in cURL Test Suite via Improper Cleanup of Global Handle to curl - 20 upvotes, $0
  159. Functional Regression in Digest Authentication: Failure to handle optional spaces and escaped quotes to curl - 20 upvotes, $0
  160. Protocol Smuggling / CRLF Injection via Gopher Protocol allows Arbitrary Command Injection to curl - 20 upvotes, $0
  161. HTTP/2 and HTTP/3 Header Injection in curl to curl - 20 upvotes, $0
  162. Incomplete Suppression of Transfer-Encoding: chunked Header in HTTP/2 After Redirect From HTTP/1.1 to curl - 20 upvotes, $0
  163. CVE-2022-27776: Auth/cookie leak on redirect to curl - 19 upvotes, $0
  164. When curl uses Schannel as TLS backend, it fails to enforce TLS 1.3 cipher suite selections correctly to curl - 19 upvotes, $0
  165. Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE Mismatch to curl - 19 upvotes, $0
  166. Insecure WebSocket Usage in curl Documentation and Examples (CWE-319: Cleartext Transmission of Sensitive Information) to curl - 19 upvotes, $0
  167. Account/Repository Takeover via Abandoned GitHub Username in curl's href_extractor.c to curl - 19 upvotes, $0
  168. ## Title Heap Use-After-Free Vulnerability in curl Leading to Potential Code Execution to curl - 19 upvotes, $0
  169. Confirmed Security Misconfigurations on curl.se (BREACH, Missing Security Headers, ETag Info Disclosure) to curl - 19 upvotes, $0
  170. File URL UNC Path Access (Windows SSRF) to curl - 19 upvotes, $0
  171. PROTOCOL-LEVEL: Persistent UDP Amplification and Cache Poisoning via Alt-Svc Logic Flaw to curl - 19 upvotes, $0
  172. Use after free in hyperfifo example to curl - 19 upvotes, $0
  173. CVE-2026-6429: netrc credential leak with reused proxy connection to curl - 19 upvotes, $0
  174. CRLF Injection via Custom HTTP Headers to curl - 19 upvotes, $0
  175. Multiple Unsafe strcpy() Function Calls Leading to Potential Buffer Overflow Vulnerabilities in cURL 8.16.1-DEV to curl - 18 upvotes, $0
  176. Stack Buffer Overflow in cURL Cookie Parsing Leads to RCE to curl - 18 upvotes, $0
  177. SMTP Command Injection Vulnerability in libcurl 8.16.0 via RFC 3461 Suffix to curl - 18 upvotes, $0
  178. Integer Overflow to Heap Overflow in DoH Response Handling to curl - 18 upvotes, $0
  179. curl built with GnuTLS backend defaults to weak crypto parameters to curl - 18 upvotes, $0
  180. Path Traversal Bypass in file:// URLs Due to Incomplete URL-Encoded Path Normalization to curl - 18 upvotes, $0
  181. Proxy-Authorization header is leaked to origin server after redirect from proxied to direct connection to curl - 18 upvotes, $0
  182. Path Traversal in curl file:// Protocol Handler Allows Unauthorized File Access to curl - 18 upvotes, $0
  183. CVE-2025-15079: libssh global knownhost override to curl - 18 upvotes, $0
  184. LM Challenge-Response Hash Always Sent in SMB Authentication to curl - 18 upvotes, $0
  185. CURLOPT_UNRESTRICTED_AUTH Dangerous Default Documentation Gap to curl - 18 upvotes, $0
  186. Cookie attribute TAB injection regression in Set-Cookie parsing to curl - 18 upvotes, $0
  187. libcurl 8.20.0 incomplete fix for CVE-2026-7168: changing only CURLOPT_PROXYPORT leaks stale Proxy Digest auth to a different proxy to curl - 18 upvotes, $0
  188. CVE-2024-2466: TLS certificate check bypass with mbedTLS to curl - 17 upvotes, $0
  189. CVE-2025-0725: gzip integer overflow to curl - 17 upvotes, $0
  190. int overflow in krb5_read_data() leads to (possible) massive recv() write to curl - 17 upvotes, $0
  191. Race condition on global gss_context during SOCKS5 GSS-API negotiation in libcurl to curl - 17 upvotes, $0
  192. Use of Deprecated strcpy() with User-Controlled Environment Variable in Memory Debug Initialization to curl - 17 upvotes, $0
  193. Infinite loop issue in the state machine of the curl project to curl - 17 upvotes, $0
  194. Certificate Hostname Validation Bypass via Leading Dot in Hostname to curl - 17 upvotes, $0
  195. Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 17 upvotes, $0
  196. CVE-2025-14524: bearer token leak on cross-protocol redirect to curl - 17 upvotes, $0
  197. libcurl: Improper Authentication State Management on Cross-Protocol Redirects to curl - 17 upvotes, $0
  198. In curl's SASL OAUTHBEARER authentication, including the SOH character (0x01) in the username corrupts the message structure. to curl - 17 upvotes, $0
  199. Connection Reuse Ignores OAuth Bearer Token Mismatch to curl - 17 upvotes, $0
  200. Unbounded GZIP Decompression Leading to Event-Loop Starvation to curl - 17 upvotes, $0
  201. Digest Auth State Leak on Cross-Origin Redirect via Netrc - Username and Password Hash Sent to Wrong Host to curl - 17 upvotes, $0
  202. SSL session-cache peer key omits signature_algorithms: strict-sigalg handle silently resumes a permissive sibling's session to curl - 17 upvotes, $0
  203. libcurl: HTTP/1.x bare LF byte in response header value enables cookie jar pollution and POST body/credential exfiltration via redirect — RC=0, curl 8 to curl - 17 upvotes, $0
  204. Duplicate chunked Transfer-Encoding lets a malicious origin smuggle a response across reused HTTP proxy connections to curl - 17 upvotes, $0
  205. mbedTLS / wolfSSL / rustls backends silently skip hostname verification when CURLOPT_SSL_VERIFYPEER=0 to curl - 17 upvotes, $0
  206. CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c to curl - 16 upvotes, $0
  207. CVE-2022-43552: HTTP Proxy deny use-after-free to curl - 16 upvotes, $0
  208. CVE-2023-23916: HTTP multi-header compression denial of service to curl - 16 upvotes, $0
  209. Speculative Execution Side-Channel in curl to curl - 16 upvotes, $0
  210. Use-after-free when POST body buffer is freed before transfer to curl - 16 upvotes, $0
  211. Buffer Overflow in WebSocket Handshake (lib/ws.c:1287) to curl - 16 upvotes, $0
  212. libcurl FTP path normalization flaw allows decoded %2e%2e → CWD .. and directory escape (Path Traversal, CWE-22) to curl - 16 upvotes, $0
  213. HAProxy Connection Reuse leads to IP Spoofing and mTLS Context Smuggling to curl - 16 upvotes, $0
  214. Cross‑Layer State Confusion in libcurl: Credential & Key‑Material Persistence Across Redirect / Connection Reuse Boundaries to curl - 16 upvotes, $0
  215. Telnet Suboption Buffer Pointer Underflow in lib/telnet.c leads to Out-of-Bounds Read to curl - 16 upvotes, $0
  216. SMTP CRLF Injection & Protocol Desynchronization in libcurl to curl - 16 upvotes, $0
  217. Missing server identity policy enforcement in SSH connection reuse allows host key verification bypass via pool poisoning to curl - 16 upvotes, $0
  218. Mentioned unites are at the same time .Then we have to increase the bounty. to curl - 16 upvotes, $0
  219. UAF read in mev_pollset_diff() trace path after curl_easy_pause() in socket callback to curl - 16 upvotes, $0
  220. Format string vulnerability, curl_msnprintf() function to curl - 15 upvotes, $0
  221. Use after free (or assert triggered) with failed allocations in openssl to curl - 15 upvotes, $0
  222. Unsafe Global IFS Modification in OS400 Shell Script Enables Command Injection and Parsing Flaws (CWE-78/CWE-20) to curl - 15 upvotes, $0
  223. Incorrect sizeof() in Rustls Backend Memory Allocation to curl - 15 upvotes, $0
  224. Path Traversal in file:// protocol allows Arbitrary File Read to curl - 15 upvotes, $0
  225. Buffer Overflow in cURL Internal printf Function to curl - 15 upvotes, $0
  226. HTTP/2 PUSH_PROMISE header loss on OOM bypasses scheme validation (regression of 2e8c922a89) to curl - 15 upvotes, $0
  227. Improper enforcement of CURLOPT_SOCKS5_AUTH due to missing reuse key validation in libcurl to curl - 15 upvotes, $0
  228. no_proxy IDN mismatch: Unicode hostnames bypass proxy exclusion list to curl - 15 upvotes, $0
  229. Integer Overflow/Signedness Mismatch in Printf Precision for HTTP/2 Trailer Headers to curl - 15 upvotes, $0
  230. CURLOPT_PROXY_CAINFO_BLOB silently activates native CA store on Apple builds to curl - 15 upvotes, $0
  231. TLS conn reuse and session cache ignore fsslctx callback and ssl_config_data flags ( incomplete fix variant of 7541ae569 ) to curl - 15 upvotes, $0
  232. CVE-2021-22897: schannel cipher selection surprise to curl - 14 upvotes, $0
  233. CVE-2021-22945: UAF and double-free in MQTT sending to curl - 14 upvotes, $0
  234. HTTP/2 CONTINUATION Flood Vulnerability to curl - 14 upvotes, $0
  235. Stack-based Buffer Overflow in TELNET NEW_ENV Option Handling to curl - 14 upvotes, $0
  236. Elevation of Privileges (EoP) vulnerabilities related to the some easy_options on Windows to curl - 14 upvotes, $0
  237. curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments to curl - 14 upvotes, $0
  238. curl --continue-at confusion to curl - 14 upvotes, $0
  239. access notes without permission to curl - 14 upvotes, $0
  240. Exposure of Hard-coded Private Keys and Credentials in curl Source Repository (CWE-321) to curl - 14 upvotes, $0
  241. Unsafe use of strcpy in Curl_ldap_err2string (packages/OS400/os400sys.c) — stack-buffer-overflow (PoC + ASan) to curl - 14 upvotes, $0
  242. Heap Buffer Overflow in TFTP to curl - 14 upvotes, $0
  243. MQTT Protocol Violation & Integer Overflow in libcurl to curl - 14 upvotes, $0
  244. IMAP Protocol Desynchronization and Response Smuggling via Naive Literal Parsing to curl - 14 upvotes, $0
  245. CVE-2022-35252: control code in cookie denial of service to curl - 13 upvotes, $0
  246. Authorization Header Leak via --location-trusted in Curl to curl - 13 upvotes, $0
  247. Title: Remote Code Execution (RCE) via Arbitrary Library Loading in --engine option to curl - 13 upvotes, $0
  248. Memory leak in Curl_auth_create_ntlm_type3_message to curl - 13 upvotes, $0
  249. Denial of Service (DoS) vulnerability in dedotdotify() URL path normalization to curl - 13 upvotes, $0
  250. Alt-Svc bypasses credential leak protection (CVE-2018-1000007) to curl - 13 upvotes, $0
  251. CVE-2025-15224: libssh key passphrase bypass without agent set to curl - 13 upvotes, $0
  252. Function do_pubkey() can have out-of-bound read issue to curl - 13 upvotes, $0
  253. Security Vulnerability Report: Protocol Injection via Programmatic Options to curl - 13 upvotes, $0
  254. libcurl reuses a learned RTSP Session header across different hosts on the same easy handle, enabling cross-host session leak and replay to curl - 13 upvotes, $0
  255. CVE-2026-4873: connection reuse ignores TLS requirement to curl - 13 upvotes, $0
  256. cookie: case-insensitive path comparison in replace_existing() allows cookie eviction across distinct paths to curl - 13 upvotes, $0
  257. OpenSSL TLS 1.2 session resumption accepts expired server certificates in libcurl to curl - 13 upvotes, $0
  258. Secure cookies leaked to HTTP origins through HTTPS forwarding proxy to curl - 13 upvotes, $0
  259. CVE-2023-27537: HSTS double-free to curl - 12 upvotes, $0
  260. CVE-2024-2398: HTTP/2 push headers memory-leak to curl - 12 upvotes, $0
  261. Unicode-to-ASCII conversion on Windows can lead to argument injection and more to curl - 12 upvotes, $0
  262. OS Command Injection in scripts/firefox-db2pem.sh via untrusted certificate nicknames to curl - 12 upvotes, $0
  263. Missing enforcement of SFTP quote syntax can lead to operation on wrong object to curl - 12 upvotes, $0
  264. CURLX_SET_BINMODE(NULL) can call fileno(NULL) and cause undefined behavior / crash to curl - 12 upvotes, $0
  265. runs javascript on powershell when it shouldnt to curl - 12 upvotes, $0
  266. Stack Buffer Overflow in cURL wolfSSL Backend (lib/vtls/wolfssl.c) to curl - 12 upvotes, $0
  267. A logic error in detect_proxy caused truncation of environment variable names for long protocol schemes. to curl - 12 upvotes, $0
  268. Security hardening: missing integer overflow check in curl_load_library() to curl - 12 upvotes, $0
  269. CVE-2026-5773: wrong reuse of SMB connection to curl - 12 upvotes, $0
  270. libssh SFTP initialization ignores CURLOPT_TIMEOUT, hangs indefinitely to curl - 12 upvotes, $0
  271. CURLOPT_HSTS_CTRL disables shared HSTS without share guard — use-after-free and double-free to curl - 12 upvotes, $0
  272. Shared HSTS cache accessed without lock to curl - 12 upvotes, $0
  273. CURLOPT_PROXY_CRLFILE / CURLOPT_PROXY_ISSUERCERT / CURLOPT_PROXY_ISSUERCERT_BLOB silently ignored on backends that don't support them to curl - 12 upvotes, $0
  274. curl External-Controlled Filename in --url @file Leads to Arbitrary File Overwrite to curl - 12 upvotes, $0
  275. CURLOPT_HAPROXY_CLIENT_IP lacks input validation, enabling HAProxy PROXY protocol injection to curl - 12 upvotes, $0
  276. Use-after-free in mev_forget_socket when curl_easy_pause() is called from a CURL_POLL_REMOVE socket callback (incomplete fix of CVE-2026-9080) to curl - 12 upvotes, $0
  277. CVE-2020-8231: Connect-only connections can use the wrong connection to curl - 11 upvotes, $0
  278. CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize to curl - 11 upvotes, $0
  279. CVE-2022-27778: curl removes wrong file on error to curl - 11 upvotes, $0
  280. CVE-2022-32208: FTP-KRB bad message verification to curl - 11 upvotes, $0
  281. CVE-2024-2379: QUIC certificate check bypass with wolfSSL to curl - 11 upvotes, $0
  282. curl allows SSH connection even if host is not in known_hosts to curl - 11 upvotes, $0
  283. Failure to strip Proxy-Authorization header on change in origin to curl - 11 upvotes, $0
  284. Stack Buffer Overflow in curl's OpenSSL Provider Handling to curl - 11 upvotes, $0
  285. Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet to curl - 11 upvotes, $0
  286. Information Disclosure at : https://curl.se/.mailmap to curl - 11 upvotes, $0
  287. SMTP CRLF Command Injection in CURLOPT_MAIL_FROM and CURLOPT_MAIL_RCPT to curl - 11 upvotes, $0
  288. Silent TLS Trust Model Hijacking via CURL_CA_BUNDLE Environment Variable Leads to MITM to curl - 11 upvotes, $0
  289. Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash to curl - 11 upvotes, $0
  290. Public-suffix cookie injection when libpsl is disabled to curl - 11 upvotes, $0
  291. Integer Overflow in curl_easy_escape() may lead to heap buffer overflow and stack memory disclosure on 32-bit platforms to curl - 11 upvotes, $0
  292. Curl Telnet Handler Buffer Overflow to curl - 11 upvotes, $0
  293. TLS peer-verification bypass via mid-transfer ssl_config mutation to curl - 11 upvotes, $0
  294. DNS domain search list followed for extant domain missing A or AAAA records to curl - 11 upvotes, $0
  295. curl-ipv4-percent-normalization-SSRF to curl - 11 upvotes, $0
  296. verify-release rebuilds from the tarball under verification, enabling pre-check command execution and false OK for a malicious curl release tarball to curl - 11 upvotes, $0
  297. heap-use-after-free in curl_easy_cleanup() called from callback to curl - 11 upvotes, $0
  298. SMB access smuggling via FILE URL on Windows to curl - 10 upvotes, $0
  299. CVE-2021-22946: Protocol downgrade required TLS bypassed to curl - 10 upvotes, $0
  300. Heap Buffer Overflow in libcurl curl_slist_append via Unterminated String to curl - 10 upvotes, $0
  301. [High] MITM via Insecure CA Path Handling in cURL (--capath, CURLOPT_CAPATH) (CWE-494: Download of Code Without Integrity Check) to curl - 10 upvotes, $0
  302. curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things to curl - 10 upvotes, $0
  303. arbitrary file read via file:// path traversal with --path-as-is to curl - 10 upvotes, $0
  304. Git repository found to curl - 10 upvotes, $0
  305. information disclosure to curl - 10 upvotes, $0
  306. Path Traversal in SFTP QUOTE command leads to Arbitrary File Write and potential RCE to curl - 10 upvotes, $0
  307. curl’s persistence files inherit world-readable/writable perms from umask, leaking and tampering with cookies/HSTS/Alt-Svc caches to curl - 10 upvotes, $0
  308. Logical Flaw in curl_url_set Leads to Inconsistent Query Parameter Encoding to curl - 10 upvotes, $0
  309. libcurl WebSocket handshake accepts any Sec-WebSocket-Accept to curl - 10 upvotes, $0
  310. MQTT: Missing upper bound on incoming Remaining Length allows server-controlled long wait to curl - 10 upvotes, $0
  311. Directory listing vulnerability is disclosing names and emails, widespread (thousands of records, publicly accessible without auth) to curl - 10 upvotes, $0
  312. FTP entrypath accepts 0xFF (Telnet IAC) through incomplete ISCNTRL filter, sent on wire via CWD on connection reuse to curl - 10 upvotes, $0
  313. Trailing-dot IPv4 URL bypasses IP-address guard, allows wildcard DNS SAN match to curl - 10 upvotes, $0
  314. curl cross-origin HTTPS redirect reuses TLS client certificate for unintended second-origin mTLS authentication to curl - 10 upvotes, $0
  315. SOCKS5 no-auth accepted despite username/password-only authentication to curl - 10 upvotes, $0
  316. Trailing-Dot Hostname in Redirect Silently Strips Client Certificate and Auth Credentials to curl - 10 upvotes, $0
  317. CVE-2022-27780: percent-encoded path separator in URL host to curl - 9 upvotes, $0
  318. Cache purge requests are not authenticated to curl - 9 upvotes, $0
  319. Memory leak from doh_write_cb to curl - 9 upvotes, $0
  320. curl_easy_header runs at O(N) or worse and can be abused to use minute(s) of CPU time to curl - 9 upvotes, $0
  321. Heap buffer overflow vulnerability in conncache.c: incorrect use of pointer arrays resulting in out-of-bounds memory writes. to curl - 9 upvotes, $0
  322. Disclosure of email addresses to curl - 9 upvotes, $0
  323. Vulnerability Report: Local File Disclosure via file:// Protocol in cURL to curl - 9 upvotes, $0
  324. Use of Deprecated strcpy() with Fixed-Size Buffers in Progress Time Formatting to curl - 9 upvotes, $0
  325. libcurl MQTT PUBLISH length overflow (heap overflow) to curl - 9 upvotes, $0
  326. Arbitrary Configuration File Inclusion: via External Control of File Name or Path to curl - 9 upvotes, $0
  327. Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 9 upvotes, $0
  328. WebSocket Logic Error: Control Frame (PING/PONG) Starvation causes Connection Drop (DoS) during large transfers to curl - 9 upvotes, $0
  329. CRLF Injection in Gopher Protocol (lib/gopher.c) to curl - 9 upvotes, $0
  330. HTTP Request Smuggling and SSRF via CRLF Injection in Curl_add_custom_headers to curl - 9 upvotes, $0
  331. CRLF Injection in HAProxy PROXY Protocol via CURLOPT_HAPROXY_CLIENT_IP allows IP spoofing and protocol injection to curl - 9 upvotes, $0
  332. ignoring 'options' when doing connection reuse to curl - 9 upvotes, $0
  333. # SCURLOPT_SSH_KNOWNHOSTS and host fingerprint pins are silently bypassed when an SSH connection is reused from the connection pool to curl - 9 upvotes, $0
  334. HSTS multi-trailing-dot bypass-ish: possible incomplete fix for CVE-2022-30115 to curl - 9 upvotes, $0
  335. RTSP Digest auth state leaks across origins on reused libcurl easy handle to curl - 9 upvotes, $0
  336. Arbitrary File Read via Unsanitized curl Usage Results in Sensitive File Exposure to curl - 8 upvotes, $0
  337. Free of uninitialized pointer in doh_decode_rdata_name() to curl - 8 upvotes, $0
  338. Path Traversal Vulnerability in curl via Unsanitized IPFS_PATH Environment Variable to curl - 8 upvotes, $0
  339. Buffer Overflow in curl's Rustls Backend to curl - 8 upvotes, $0
  340. Double free caused by mqtt_doing() to curl - 8 upvotes, $0
  341. Potential XSS vector in curl via unsanitized URL parameter handling to curl - 8 upvotes, $0
  342. Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink() to curl - 8 upvotes, $0
  343. SOCKS5 Heap Buffer Overflow via Malicious HTTP Redirect with Oversized Hostname to curl - 8 upvotes, $0
  344. libcurl MQTT CURLOPT_POSTFIELDSIZE_LARGE overflow leads to immediate DoS to curl - 8 upvotes, $0
  345. SMTP CRLF Injection in curl/libcurl via MAIL FROM/RCPT TO parameters to curl - 8 upvotes, $0
  346. Command Injection - CRITICISM to curl - 8 upvotes, $0
  347. Hash exposed in public repository to curl - 8 upvotes, $0
  348. Malicious server forces .curlrc creation via curl -OJ leading to local file exfiltration to curl - 8 upvotes, $0
  349. Off-by-One Buffer Overflow in SMB Path Handler to curl - 8 upvotes, $0
  350. Terminal Output Not Great to curl - 8 upvotes, $0
  351. Curl Alt-Svc Parser Stack Buffer Overflow to curl - 8 upvotes, $0
  352. Heap Overflow in cURL AmigaOS Socket Implementation to curl - 8 upvotes, $0
  353. Heap Buffer Over-read in lib/http2.c (on_header) handling PUSH_PROMISE frames to curl - 8 upvotes, $0
  354. Stack Buffer Overflow in mprintf.c formatting function (fallback path) to curl - 8 upvotes, $0
  355. State Isolation Failure in Multiplexed Connections (Shared Auth Context) to curl - 8 upvotes, $0
  356. Use-After-Free in curl_easy_nextheader when reusing header handle across requests to curl - 8 upvotes, $0
  357. Gopher Protocol Command Injection (SSRF Smuggling) to curl - 8 upvotes, $0
  358. Digest Authentication Header Injection to curl - 8 upvotes, $0
  359. Use-after-free in curl_easy_ssls_export() during callback re-entrancy to curl - 8 upvotes, $0
  360. rustls backend silently ignores CURLOPT_CRLFILE when native CA store is active to curl - 8 upvotes, $0
  361. lib/ldap.c follows attacker-controlled LDAP referrals and binds to a second server; WinLDAP builds leak current logon credentials (confirmed on Window to curl - 8 upvotes, $0
  362. CVE-2021-22890: TLS 1.3 session ticket proxy host mixup to curl - 7 upvotes, $0
  363. CVE-2021-22898: TELNET stack contents disclosure to curl - 7 upvotes, $0
  364. CVE-2021-22947: STARTTLS protocol injection via MITM to curl - 7 upvotes, $0
  365. CVE-2022-27774: Credential leak on redirect to curl - 7 upvotes, $0
  366. CVE-2022-27775: Bad local IPv6 connection reuse to curl - 7 upvotes, $0
  367. CVE-2022-30115: HSTS bypass via trailing dot to curl - 7 upvotes, $0
  368. CVE-2022-35260: .netrc parser out-of-bounds access to curl - 7 upvotes, $0
  369. CVE-2022-42915: HTTP proxy double-free to curl - 7 upvotes, $0
  370. CVE-2022-43551: Another HSTS bypass via IDN to curl - 7 upvotes, $0
  371. curl file writing susceptible to symlink attacks to curl - 7 upvotes, $0
  372. CVE-2023-23915: HSTS amnesia with --parallel to curl - 7 upvotes, $0
  373. Incorrect Encoding Conversion in hostname results in indeterminate SSRF vulnerabilities to curl - 7 upvotes, $0
  374. Improper Restriction of Authentication Attempts in cURL to curl - 7 upvotes, $0
  375. [High] Arbitrary File Write via Path Traversal in cURL CLI (-o, --output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) to curl - 7 upvotes, $0
  376. Buffer over-read,, Missing NUL termination in addvariable() causes undefined behavior to curl - 7 upvotes, $0
  377. Certificate Pinning Bypass with wolfSSL backend over HTTP/3 to curl - 7 upvotes, $0
  378. inconsistently Rejection Logic in file:// URLs with Authority to curl - 7 upvotes, $0
  379. Integer-underflow leads to heap over-read in TFTP implementation to curl - 7 upvotes, $0
  380. Heap-buffer-overflow in Curl_ssl_push_certinfo_len() — sole bounds check is DEBUGASSERT to curl - 7 upvotes, $0
  381. HTTP/2 proxy CONNECT tunnel unbounded 1xx chain (missing Curl_bump_headersize cap in cf-h2-proxy.c) to curl - 7 upvotes, $0
  382. TLS verifyhost bypass in rustls, mbedTLS, and wolfSSL when verifypeer=0 to curl - 7 upvotes, $0
  383. TFTP upload ignores --continue-at / CURLOPT_RESUME_FROM and leaks skipped local file prefix to curl - 7 upvotes, $0
  384. curl/libcurl vulnerable to TLS truncation attacks to curl - 7 upvotes, $0
  385. CVE-2026-12064: proto-default skips SSH verification to curl - 7 upvotes, $0
  386. ssh_config_matches is dead code: unauthorized SSH key reuse to curl - 7 upvotes, $0
  387. setopt(VERIFYPEER) from callback bypasses TLS verify on connection reuse to curl - 7 upvotes, $0
  388. Github wikis are editable by anyone #Githubwikistakeover to curl - 6 upvotes, $0
  389. CVE-2019-5481: krb5: double-free in read_data() after realloc() fail to curl - 6 upvotes, $0
  390. SSRF via maliciously crafted URL due to host confusion to curl - 6 upvotes, $0
  391. --libcurl code injection via trigraphs to curl - 6 upvotes, $0
  392. CVE-2022-22576: OAUTH2 bearer bypass in connection re-use to curl - 6 upvotes, $0
  393. CVE-2022-27782: TLS and SSH connection too eager reuse to curl - 6 upvotes, $0
  394. CVE-2022-32207: Unpreserved file permissions to curl - 6 upvotes, $0
  395. CVE-2023-23914: curl HSTS ignored on multiple requests to curl - 6 upvotes, $0
  396. CVE-2023-28320: siglongjmp race condition to curl - 6 upvotes, $0
  397. Denial of Service in curl Request - HTTP headers eat all memory to curl - 6 upvotes, $0
  398. -H with space prefix leads to previous header injection when used with --proxy to curl - 6 upvotes, $0
  399. netrc crlf injection to curl - 6 upvotes, $0
  400. SMTP Protocol Injection via CRLF in CURLOPT_MAIL_FROM leading to Email Spoofing to curl - 6 upvotes, $0
  401. CVE-2026-11564: Native CA trust persist to curl - 6 upvotes, $0
  402. Active Mixed Content over HTTPS to curl - 5 upvotes, $0
  403. CVE-2021-22876: Automatic referer leaks credentials to curl - 5 upvotes, $0
  404. CVE-2021-22922: Wrong content via metalink not discarded to curl - 5 upvotes, $0
  405. CVE-2021-22926: CURLOPT_SSLCERT mixup with Secure Transport to curl - 5 upvotes, $0
  406. CVE-2021-22924: Bad connection reuse due to flawed path name checks to curl - 5 upvotes, $0
  407. Remote memory disclosure vulnerability in libcurl on 64 Bit Windows to curl - 5 upvotes, $0
  408. CVE-2022-27779: cookie for trailing dot TLD to curl - 5 upvotes, $0
  409. Credential leak on redirect to curl - 5 upvotes, $0
  410. CVE-2022-27781: CERTINFO never-ending busy-loop to curl - 5 upvotes, $0
  411. TLS Cipher Misconfiguration in HTTP/3/QUIC Support to curl - 5 upvotes, $0
  412. curl mishandles %0c%0b sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection to curl - 5 upvotes, $0
  413. Double free in tool_ssls_load() to curl - 5 upvotes, $0
  414. CRLF Injection / Protocol Smuggling in libcurl via CURLOPT_USERNAME (IMAP) to curl - 5 upvotes, $0
  415. CRLF Injection in HTTP header values allows arbitrary header injection to curl - 5 upvotes, $0
  416. Heap Out-of-Bounds Read in lib/http2.c via Malformed PUSH_PROMISE Headers to curl - 5 upvotes, $0
  417. integer Overflow in MQTT Protocol Handling Allows Bypassing Message Size Limit to curl - 5 upvotes, $0
  418. SMTP Command Injection via CRLF in libcurl MAIL_FROM / MAIL_RCPT (lib/smtp.c) to curl - 5 upvotes, $0
  419. NULL pointer dereference in libcurl URL API redirect_url() with CURLU_DEFAULT_SCHEME to curl - 5 upvotes, $0
  420. Low priority HSTS bypass in curl_easy_duphandle() to curl - 5 upvotes, $0
  421. Use-after-free in curl_easy_duphandle() with HTTP/2 stream-dependency tree to curl - 5 upvotes, $0
  422. libcurl 8.20.0 ignores HTTP Digest domain protection space and preemptively leaks Digest auth outside the declared scope to curl - 5 upvotes, $0
  423. CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop to curl - 5 upvotes, $0
  424. HTTPS proxy connection reuse lets one easy handle inherit another handle's mTLS-authenticated proxy session to curl - 5 upvotes, $0
  425. Signed integer overflow in tool_progress_cb() to curl - 4 upvotes, $0
  426. Invalid write (or double free) triggers curl command line tool crash to curl - 4 upvotes, $0
  427. Integer overflows in tool_operate.c at line 1541 to curl - 4 upvotes, $0
  428. CVE-2021-22923: Metalink download sends credentials to curl - 4 upvotes, $0
  429. CURLOPT_SSH_HOST_PUBLIC_KEY_MD5 bypass if string not 32 chars to curl - 4 upvotes, $0
  430. Memory leak in CURLOPT_XOAUTH2_BEARER to curl - 4 upvotes, $0
  431. error parse uri path in curl to curl - 4 upvotes, $0
  432. CVE-2022-32206: HTTP compression denial of service to curl - 4 upvotes, $0
  433. CVE-2022-32205: Set-Cookie denial of service to curl - 4 upvotes, $0
  434. libssh backend CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 validation bypass to curl - 4 upvotes, $0
  435. CVE-2023-27533: Telnet option IAC injection to curl - 4 upvotes, $0
  436. CVE-2023-27535: FTP too eager connection reuse to curl - 4 upvotes, $0
  437. CVE-2023-27536: GSS delegation too eager connection re-use to curl - 4 upvotes, $0
  438. CVE-2023-27538: SSH connection too eager reuse still to curl - 4 upvotes, $0
  439. OS Command Injection (subprocess Module Usage) to curl - 4 upvotes, $0
  440. Heap buffer overflow in Curl_ipv4_resolve_r due to incorrect buffer alignment and size calculation on AmigaOS to curl - 4 upvotes, $0
  441. MQTT: unsigned integer underflow bypasses MAX_MQTT_MESSAGE_SIZE check to curl - 4 upvotes, $0
  442. Stack exhaustion in MIME multipart reading with deeply nested subparts to curl - 4 upvotes, $0
  443. CVE-2026-10536: HTTP/2 stream-dependency tree UAF to curl - 4 upvotes, $0
  444. CVE-2026-11586: WS Auto-PONG memory exhaustion to curl - 4 upvotes, $0
  445. curl overwrites local file with -J option if file non-readable, but file writable. to curl - 3 upvotes, $0
  446. CVE-2020-8285: FTP wildcard stack overflow to curl - 3 upvotes, $0
  447. Abusing URL Parsers by long schema name to curl - 3 upvotes, $0
  448. Poll loop/hang on incomplete HTTP header to curl - 3 upvotes, $0
  449. Integer overflow in the source code tool_cb_prg.c to curl - 3 upvotes, $0
  450. CVE-2021-22925: TELNET stack contents disclosure again to curl - 3 upvotes, $0
  451. Denial of Service vulnerability in curl when parsing MQTT server response to curl - 3 upvotes, $0
  452. Credential leak when use two url to curl - 3 upvotes, $0
  453. CVE-2022-32221: POST following PUT confusion to curl - 3 upvotes, $0
  454. CVE-2023-27534: SFTP path ~ resolving discrepancy to curl - 3 upvotes, $0
  455. CVE-2023-28322: more POST-after-PUT confusion to curl - 3 upvotes, $0
  456. Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations to curl - 3 upvotes, $0
  457. CURLOPT_COOKIE leaked to cross-origin redirect target — CURLOPT_UNRESTRICTED_AUTH bypass for the STRING_COOKIE path to curl - 3 upvotes, $0
  458. CURLSHOPT_UNSHARE race can cause UAF in shared SSL session cache during HTTPS transfer to curl - 3 upvotes, $0
  459. Heap Buffer Overflow (READ of size 1) in ourWriteOut to curl - 2 upvotes, $0
  460. Libcurl ocasionally sends HTTPS traffic to port 443 rather than specified port 8080 to curl - 2 upvotes, $0
  461. Integer overlow in "header_append" function to curl - 2 upvotes, $0
  462. curl on Windows can be forced to execute code via OpenSSL environment variables to curl - 2 upvotes, $0
  463. Proxy-Authorization header carried to a new host on a redirect to curl - 2 upvotes, $0
  464. Binary output bypass to curl - 2 upvotes, $0
  465. CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 comparison disaster to curl - 2 upvotes, $0
  466. Certificate authentication re-use on redirect to curl - 2 upvotes, $0
  467. Cookie injection from non-secure context to curl - 2 upvotes, $0
  468. Heap overflow via HTTP/2 PUSH_PROMISE to curl - 2 upvotes, $0
  469. CVE-2022-42916: HSTS bypass via IDN to curl - 2 upvotes, $0
  470. CVE-2023-28321: IDN wildcard match to curl - 2 upvotes, $0
  471. Proxy CONNECT response poisoning via authentication retry in cf-h1-proxy.c (libcurl) to curl - 2 upvotes, $0
  472. curl/libcurl 8.20.0 NOPROXY bypass via uppercase-hex IPv4 aliases leaks off-proxy Basic credentials to the configured proxy to curl - 2 upvotes, $0
  473. CVE-2026-9545: exposing HTTP/3 early data to curl - 2 upvotes, $0
  474. CVE-2026-8932: incomplete mTLS config matching in conn reuse to curl - 2 upvotes, $0
  475. CVE-2026-9080: UAF after pause in socket callback to curl - 2 upvotes, $0
  476. CVE-2026-9079: stale proxy password leak to curl - 2 upvotes, $0
  477. CVE-2026-9546: sending old referer to curl - 2 upvotes, $0
  478. Insecure Frame (External) to curl - 1 upvotes, $0
  479. Parallel upload hangs curl if upload file not found to curl - 1 upvotes, $0
  480. libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823 to curl - 1 upvotes, $0
  481. Race condition with CURL_LOCK_DATA_CONNECT can cause connections to be used at the same time to curl - 1 upvotes, $0
  482. Division by zero if terminal width is 2 to curl - 1 upvotes, $0
  483. Unexpected access to process open files via file:///proc/self/fd/n to curl - 1 upvotes, $0
  484. use after free in cookie.c to curl - 1 upvotes, $0
  485. Potential invocation of qsort on uninitialized memory during cookie save to curl - 1 upvotes, $0
  486. Resource leak when using a normal site as DOH server to curl - 1 upvotes, $0
  487. Buffer write overflow when forming dns over http request to curl - 1 upvotes, $0
  488. Integer overflow at line 1603 in the src/operator.c file to curl - 1 upvotes, $0
  489. huge COLUMNS causes progress-bar to buffer overflow to curl - 1 upvotes, $0
  490. Inadequate Cryptographic Key Size and Insecure Cryptographic Mode. File Name :- curl_ntlm_core.c to curl - 1 upvotes, $0
  491. Occasional use-after-free in multi_done() libcurl-7.81.0 to curl - 1 upvotes, $0
  492. Use of Unsafe function || Strcpy to curl - 1 upvotes, $0
  493. curl proceeds with unsafe connections when -K file can't be read to curl - 1 upvotes, $0
  494. KRB-FTP: Security level downgrade to curl - 1 upvotes, $0
  495. curl "globbing" can lead to denial of service attacks to curl - 1 upvotes, $0
  496. SMTP connection reuse ignores --ssl-reqd / CURLOPT_USE_SSL and reuses a clear-text STARTTLS session on current master to curl - 1 upvotes, $0
  497. PRE_PROXY change leaks stale Proxy Digest state across proxy-chain boundary to curl - 1 upvotes, $0
  498. CVE-2026-11856: cross-origin Digest auth state leak to curl - 1 upvotes, $0
  499. CVE-2026-8458: wrong reuse for different services to curl - 1 upvotes, $0
  500. CVE-2026-8926: password leak with netrc and user in URL to curl - 1 upvotes, $0
  501. CVE-2026-8925: SASL double-free to curl - 1 upvotes, $0
  502. CVE-2026-8927: env-set cross-proxy Digest auth state leak to curl - 1 upvotes, $0
  503. CVE-2026-8286: wrong STARTTLS connection reuse to curl - 1 upvotes, $0
  504. CVE-2026-9547: SSH improper host validation to curl - 1 upvotes, $0
  505. libcurl upload read callbacks miss recursive API guard, allowing prohibited multi API reentry and ASAN-confirmed UAF to curl - 1 upvotes, $0
  506. Port and service scanning on localhost due to improper URL validation. to curl - 0 upvotes, $0
  507. Data race conditions reported by helgrind when performing parallel DNS queries in libcurl to curl - 0 upvotes, $0
  508. Only OpenSSL handles a CRL when passed in via CApath to curl - 0 upvotes, $0
  509. curl successfully matches IP address literal in URL against IP address literal in certificate Common Name to curl - 0 upvotes, $0
  510. Curl_auth_create_plain_message integer overflow leads to heap buffer overflow to curl - 0 upvotes, $0
  511. curl still vulnerable to SMB access smuggling via FILE URL on Windows to curl - 0 upvotes, $0
  512. Incorrect IPv6 literal parsing leads to validated connection to unexpected https server. to curl - 0 upvotes, $0
  513. Double-free of trailers_buf' on Curl_http_compile_trailers()` failure to curl - 0 upvotes, $0
  514. match to curl - 0 upvotes, $0
  515. Integer overflows in unescape_word() to curl - 0 upvotes, $0
  516. CVE-2026-8924: trailing dot domain super cookie to curl - 0 upvotes, $0