vciy

CVEs we hold for Curl

Records whose assigning authority named Curl as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9547SSH improper host validationcurl
CVE-2026-9546sending old referercurl
CVE-2026-9545exposing HTTP/3 early datacurl
CVE-2026-9080UAF after pause in socket callbackcurl
CVE-2026-9079stale proxy password leakcurl
CVE-2026-8932incomplete mTLS config matching in conn reusecurl
CVE-2026-8927env-set cross-proxy Digest auth state leakcurl
CVE-2026-8926password leak with netrc and user in URLcurl
CVE-2026-8925SASL double-freecurl
CVE-2026-8924trailing dot domain super cookiecurl
CVE-2026-8458wrong reuse for different servicescurl
CVE-2026-8286wrong STARTTLS connection reusecurl
CVE-2026-82209domain-scoped PSL domain cookiecurl
CVE-2026-82208wolfSSL CA-cache hit overrides callbackcurl
CVE-2026-80255secure cookie attribute bypass with tabcurl
CVE-2026-80231native CA store conn reusecurl
CVE-2026-80230OpenSSL pinning bypasscurl
CVE-2026-80229OpenSSL provider use-after-freecurl
CVE-2026-7168cross-proxy Digest auth state leakcurl
CVE-2026-7009OCSP stapling bypass with Apple SecTrustcurl
CVE-2026-6429netrc credential leak with reused proxy connectioncurl
CVE-2026-6276stale custom cookie host causes cookie leakcurl
CVE-2026-6253proxy credentials leak over redirect-to proxycurl
CVE-2026-5773wrong reuse of SMB connectioncurl
CVE-2026-5545wrong reuse of HTTP Negotiate connectioncurl
CVE-2026-4873connection reuse ignores TLS requirementcurl
CVE-2026-3805use after free in SMB connection reusecurl
CVE-2026-3784wrong proxy connection reuse with credentialscurl
CVE-2026-3783token leak with redirect and netrccurl
CVE-2026-19931Negotiate ambient user conn reusecurl
CVE-2026-1965bad reuse of HTTP Negotiate connectioncurl
CVE-2026-18924HTTP/2 server push UAFcurl
CVE-2026-13608OpenLDAP SASL authentication bypasscurl
CVE-2026-12064proto-default skips SSH verificationcurl
CVE-2026-11856cross-origin Digest auth state leakcurl
CVE-2026-11586WS Auto-PONG memory exhaustioncurl
CVE-2026-11564Native CA trust persistcurl
CVE-2026-11352QUIC zero-length UDP datagrams busy-loopcurl
CVE-2026-10536HTTP/2 stream-dependency tree UAFcurl
CVE-2025-9086Out of bounds read for cookie pathcurl
CVE-2025-69135WordPress Events Schedule - WordPress Events Calendar Plugin plugin <= 2.7.2 - SQL Injection vulnerabilityCurlyThemes Events Schedule - WordPress Events Calendar…
CVE-2025-5399WebSocket endless loopcurl
CVE-2025-5025No QUIC certificate pinning with wolfSSLcurl
CVE-2025-4947QUIC certificate check skip with wolfSSLcurl
CVE-2025-15224libssh key passphrase bypass without agent setcurl
CVE-2025-15079libssh global known_hosts overridecurl
CVE-2025-14819OpenSSL partial chain store policy bypasscurl
CVE-2025-14524bearer token leak on cross-protocol redirectcurl
CVE-2025-14017broken TLS options for threaded LDAPScurl
CVE-2025-13034No QUIC certificate pinning with GnuTLScurl
CVE-2025-11563wcurl path traversal with percent-encoded slashescurl
CVE-2025-10966missing SFTP host verification with wolfSSHcurl
CVE-2025-10148predictable WebSocket maskcurl
CVE-2025-0725gzip integer overflowcurl
CVE-2025-0665eventfd double closecurl
CVE-2025-0167netrc and default credential leakcurl
CVE-2024-9681HSTS subdomain overwrites parent cache entrycurl
CVE-2024-8096OCSP stapling bypass with GnuTLScurl
CVE-2024-7264ASN.1 date parser overreadcurl
CVE-2024-6874macidn punycode buffer overreadcurl
CVE-2024-6197freeing stack buffer in utf8asn1strcurl
CVE-2024-2466TLS certificate check bypass with mbedTLScurl
CVE-2024-2398HTTP/2 push headers memory-leakcurl
CVE-2024-2379QUIC certificate check bypass with wolfSSLcurl
CVE-2024-2004Usage of disabled protocolcurl
CVE-2024-11053netrc and redirect credential leakcurl
CVE-2024-0853OCSP verification bypass with TLS session reusecurl
CVE-2023-46219no title heldcurl
CVE-2023-46218no title heldcurl
CVE-2023-38546no title heldcurl
CVE-2023-38545no title heldcurl
CVE-2023-38039no title heldcurl
CVE-2021-23416Cross-site Scripting (XSS)n/a curly-bracket-parser
CVE-2020-7646no title heldn/a curlrequest
CVE-2020-28425Command Injectionn/a curljs
CVE-2019-5482no title heldn/a curl
CVE-2019-5481no title heldn/a curl
CVE-2019-5443no title heldn/a curl
CVE-2019-5436no title heldcurl
CVE-2019-5435no title heldcurl
CVE-2019-10789no title heldn/a curling.js
CVE-2018-0500no title heldn/a curl before 7.61.0
CVE-2017-8818no title heldn/a curl and libcurl before 7.57.0
CVE-2017-8817no title heldn/a curl and libcurl before 7.57.0
CVE-2017-8816no title heldn/a curl and libcurl before 7.57.0
CVE-2017-2629no title heldcurl
CVE-2016-4606no title heldn/a curl

87 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.