Articles tagged curl
-
Vulnerabilitycurl Vulnerability (CVE-2026-82208)
CVE-2026-82208 is a CVSS 7.5 high-severity flaw where libcurl silently reinstalls a cached wolfSSL trust store after a CURLOPT_SSL_CTX_FUNCTION callback replaces it, accepting certificates the callback should have rejected.
-
Vulnerabilitycurl Authentication Bypass (CVE-2026-13608)
CVE-2026-13608 is a CVSS 7.4 high-severity flaw letting a man-in-the-middle attacker bypass libcurl SASL/LDAP authentication via an incomplete handshake.
-
Vulnerabilitycurl Vulnerability (CVE-2026-82209)
CVE-2026-82209 is a CVSS 8.2 high-severity flaw where libcurl's Public Suffix List check fails to scope a cookie set by a public suffix domain, leaking it to sibling subdomains.
-
Vulnerabilitycurl Vulnerability (CVE-2026-18924)
CVE-2026-18924 is a CVSS 9.1 critical use-after-free in libcurl's HTTP/2 Server Push handling when a handle shares connections with other handles.
-
Vulnerabilitycurl Use-After-Free (CVE-2026-80229)
CVE-2026-80229 is a CVSS 7.5 high-severity use-after-free in libcurl's OpenSSL 3 provider integration when a pooled TLS connection outlives the easy handle that created it.
-
Vulnerabilitycurl Certificate Pinning Bypass (CVE-2026-80230)
CVE-2026-80230 is a CVSS 7.5 high-severity flaw where libcurl skips public-key-pinning enforcement on connections without a presented server certificate when standard peer verification is disabled.
-
Vulnerabilitycurl Authentication Flaw (CVE-2026-19931)
CVE-2026-19931 is a CVSS 9.8 critical flaw in libcurl that can send one user's HTTP request over another user's already-Negotiate-authenticated connection.
-
Vulnerabilitycurl Vulnerability (CVE-2026-80231)
CVE-2026-80231 is a CVSS 7.5 high-severity connection-reuse flaw where libcurl reuses an HTTPS connection across different Native CA Store settings.
-
Vulnerabilitycurl Vulnerability (CVE-2026-80255)
CVE-2026-80255 is a CVSS 7.5 high-severity parsing flaw where a tab character before the Secure attribute in a Set-Cookie header causes libcurl to drop the Secure flag, risking plaintext transmission.