curl

18 known vulnerabilities in curl, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-82209 CVSS 8.2 high When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where…
  • CVE-2026-82208 CVSS 7.5 high With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can…
  • CVE-2026-80255 CVSS 7.5 high A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute…
  • CVE-2026-80231 CVSS 7.5 high A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA…
  • CVE-2026-80230 CVSS 7.5 high When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and…
  • CVE-2026-80229 CVSS 7.5 high When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3…
  • CVE-2026-19931 CVSS 9.8 critical A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial…
  • CVE-2026-18924 CVSS 9.1 critical A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can…
  • CVE-2026-13608 CVSS 7.4 high A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a…
  • CVE-2026-9547 CVSS 7.4 high When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may…
  • CVE-2026-8286 CVSS 8.1 high A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even…
  • CVE-2026-7168 CVSS 5.3 medium Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the…
  • CVE-2026-6429 CVSS 5.3 medium When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first…
  • CVE-2026-6276 CVSS 7.5 high Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same…
  • CVE-2026-6253 CVSS 5.9 medium curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1…
  • CVE-2026-4873 CVSS 5.9 medium A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection…
  • CVE-2026-3783 CVSS 5.3 medium When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that…
  • CVE-2026-1965 CVSS 6.5 medium libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl…