Haxx

Curl

169 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 13.05.2026 08:28:19
  • Zuletzt bearbeitet 15.09.2026 07:16:29

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on ...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 13.05.2026 08:28:03
  • Zuletzt bearbeitet 15.09.2026 07:16:29

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credential...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 13.05.2026 08:27:42
  • Zuletzt bearbeitet 15.09.2026 07:16:28

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 13.05.2026 08:27:26
  • Zuletzt bearbeitet 15.09.2026 07:16:28

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent reque...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 13.05.2026 08:27:04
  • Zuletzt bearbeitet 15.09.2026 07:16:28

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same hos...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 11.03.2026 10:09:37
  • Zuletzt bearbeitet 14.09.2026 21:17:06

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.03.2026 10:09:21
  • Zuletzt bearbeitet 15.09.2026 07:16:27

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 11.03.2026 10:09:08
  • Zuletzt bearbeitet 15.09.2026 07:16:27

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to h...

  • EPSS 0.26%
  • Veröffentlicht 11.03.2026 10:08:52
  • Zuletzt bearbeitet 15.09.2026 07:16:27

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overh...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 08.01.2026 10:15:47
  • Zuletzt bearbeitet 15.09.2026 07:16:24

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hos...