PatchSiren

curl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH curl CVE published 2026-07-03

CVE-2026-9547

A libcurl-based application performing transfers via `SCP://` or `SFTP://` and utilizing the `CURLOPT_SSH_KEYFUNCTION` callback may silently accept an untrusted server. This occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. The vulnerability allows the connection to succeed without warning, potentially leading [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-9546

The CVE record for CVE-2026-9546 was published on 2026-07-03T07:16:25.893Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects libcurl, causing the HTTP Referer: header to persist even when explicitly cleared. Users of libcurl, particularly those handling sensitive information, should be aware of this vulnerability and take steps to mitigate it. The vulner [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-9545

CVE-2026-9545 is a high-severity vulnerability in libcurl that can lead to sensitive information disclosure. When libcurl uses a cached SSL session and early data is enabled, it may send request bytes on a new connection before enforcing certificate verification, potentially leaking sensitive information. This vulnerability affects libcurl in various environments, particularly those handling sensitive inf [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-9080

CVE-2026-9080 is a use-after-free vulnerability in libcurl, occurring when calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback. This triggers a use-after-free vulnerability because libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. The vulnerability has been assigned a CVSS score of 7.3 and a severity o [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-9079

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. This critical vulnerability affects libcurl versions between 8.8.0 and 8.21.0. Users of libcurl, particularly those using versions between 8.8.0 and 8.21.0, should review and apply patches to mi [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-8932

CVE-2026-8932 is a vulnerability in libcurl that allows for the reuse of previously created connections even when certain mTLS configuration options have been changed. This issue arises from libcurl's connection pooling mechanism, which did not properly account for changes to TLS settings related to client certificates. The vulnerability stems from the connection pooling mechanism of libcurl, which mainta [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-8926

A critical vulnerability was discovered in curl, a popular command-line tool for transferring data with URLs. The vulnerability occurs when asking curl to use a `.netrc` file to find credentials and specifying a URL with a username (without a password). In such cases, curl could wrongly get and use the password for another user set in the `.netrc` file for that host if such a one exists and there is no ma [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-8925

A critical vulnerability in curl's SASL authentication logic could lead to a double-free error, allowing potential attackers to exploit the vulnerability. The CVE record was published on 2026-07-03T07:16:24.950Z and was last modified on 2026-09-15T07:16:32.800Z. The NVD entry is currently Modified. This vulnerability affects curl deployments using SASL authentication, and defenders should assess exposure [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-8924

A flaw in curl's cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. The vulnerability has significant operational impact, particularly for users of curl who transfer data with URLs, as it could allow att [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-8286

A vulnerability exists in Curl where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. This issue has been assigned a CVSS score of 8.1 and a severity of HIGH. The vulnerability affects users of Curl who utilize STARTTLS for upgrading connections, potentially leading to security issues includin [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-11856

CVE-2026-11856 is a critical vulnerability in libcurl that wrongly passes on the `Authorization:` header field. This occurs when using libcurl to do a transfer to a specific HTTP origin and then changing the origin for a second transfer, reusing the same handle. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Users of libcurl, particularly those using Digest authentication, should [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-11586

CVE-2026-11586 is a high-severity vulnerability in Curl, a popular command-line tool for transferring data. The vulnerability has a CVSS score of 7.5 and can be exploited by a malicious server to exhaust all available memory by flooding Curl with rapid, sequential PING messages. This vulnerability affects users of Curl, especially those who use it to transfer data over the internet. The vulnerability is c [truncated]

CRITICAL curl CVE published 2026-07-03

CVE-2026-11564

A critical vulnerability was found in libcurl, a popular open-source library used for transferring data with URLs. The issue allows libcurl to keep previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. This can lead to security issues if an easy handle that first uses default native CA trust continues trusting the native platform store after t [truncated]

HIGH curl CVE published 2026-07-03

CVE-2026-11352

CVE-2026-11352 is a remote denial of service vulnerability in curl’s QUIC UDP receive function. A malicious HTTP/3 server can trigger this vulnerability against a curl or libcurl client by continuously streaming empty datagrams to indefinitely stall the client. This issue affects users of curl or libcurl clients, particularly those using version 8.18.0 up to but not including 8.21.0.

CRITICAL curl CVE published 2026-07-03

CVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the rese [truncated]

MEDIUM curl CVE published 2026-05-13

CVE-2026-7168

CVE-2026-7168 is a medium-severity vulnerability in libcurl that can lead to the unintended passing of Proxy-Authorization headers across different HTTP proxies when reusing the same handle for multiple transfers. This issue arises when using libcurl to perform transfers over specific HTTP proxies with Digest authentication. The vulnerability requires verification of libcurl installations and configuratio [truncated]

MEDIUM curl CVE published 2026-05-13

CVE-2026-6429

libcurl leaks password when using .netrc and following HTTP redirects. This vulnerability affects systems using libcurl with .netrc and HTTP redirects. Defenders should assess exposure and review vendor advisory for CVE-2026-6429. The vulnerability allows libcurl to leak the password used for the first host to the followed-to host under certain circumstances. This issue arises when libcurl is asked to bot [truncated]

HIGH curl CVE published 2026-05-13

CVE-2026-6276

CVE-2026-6276 is a vulnerability in libcurl that can cause cookies to be leaked when a custom Host header is used for an HTTP request and a second request is made using the same easy handle without the custom Host header. This issue can lead to unintended information disclosure. The vulnerability occurs due to the improper handling of custom Host headers, allowing cookies meant for the first host to be le [truncated]

MEDIUM curl CVE published 2026-05-13

CVE-2026-6253

CVE-2026-6253 debrief based on the supplied source corpus. The CVE record was published on 2026-05-13T13:01:56.570Z and has not been modified since then. This medium-severity vulnerability in curl can lead to potential credential leaks when using multiple proxies for different URL schemes. Defenders should assess exposure and verify curl configurations, especially those using multiple proxies for differen [truncated]

MEDIUM curl CVE published 2026-05-13

CVE-2026-5545

CVE-2026-5545 is a medium-severity vulnerability in libcurl that can lead to unintended connection reuse, potentially causing authentication issues. The vulnerability arises from a logical error in libcurl's connection reuse mechanism, which can cause a request to wrongfully reuse an existing connection authenticated with different credentials. This issue can occur when an application uses Negotiate authe [truncated]

MEDIUM curl CVE published 2026-05-13

CVE-2026-4873

A vulnerability in curl allows an existing unencrypted connection from the same connection pool to be reused for a connection requiring TLS. If an initial transfer is made in clear-text via IMAP, SMTP, or POP3, a subsequent request to that same host bypasses the TLS requirement and transmits data unencrypted. This issue affects systems using curl with clear-text protocols, potentially leading to unencrypt [truncated]

HIGH curl CVE published 2026-03-11

CVE-2026-3805

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-11T11:16:00.967Z and has not been modified since then. The vulnerability affects curl versions between 8.13.0 and 8.19.0, causing crashes or data corruption when doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. System admini [truncated]

MEDIUM curl CVE published 2026-03-11

CVE-2026-3783

CVE-2026-3783 debrief: The curl project has fixed a vulnerability where an OAuth2 bearer token could be leaked to a second hostname when a redirect occurs. This issue arises when an OAuth2 bearer token is used for an HTTP(S) transfer that performs a redirect to a second URL. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `de [truncated]

MEDIUM curl CVE published 2026-03-11

CVE-2026-1965

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. This issue arises from a logical error in the code that manages connection reuse, potentially leading to authentication bypass. Applications using libcurl for Negotiate authentication may be vulnerable if they send multiple requests to the same server with different credentials w [truncated]

LOW curl CVE published 2026-01-08

CVE-2025-15224

CVE-2025-15224 is a vulnerability in curl that affects SSH-based transfers using SCP or SFTP with public key authentication. The vulnerability allows curl to incorrectly use a locally running SSH agent for public key authentication. Defenders should verify curl versions and configurations, assess exposure, and update curl to version 8.18.0 or later if necessary. The CVE record was published on 2026-01-08T [truncated]

MEDIUM curl CVE published 2026-01-08

CVE-2025-15079

CVE-2025-15079 is a medium-severity vulnerability in libcurl that could allow mistaken connections to hosts not present in the specified known_hosts file if they were added as recognized in the libssh global known_hosts file. This issue affects curl versions from 7.58.0 to 8.18.0. The vulnerability arises during SSH-based transfers using either SCP or SFTP when setting the known_hosts file. To address thi [truncated]

MEDIUM curl CVE published 2026-01-08

CVE-2025-14524

CVE-2025-14524 is a medium-severity vulnerability in curl that can lead to OAuth2 bearer token leaks via cross-protocol redirects. The vulnerability affects curl versions between 7.33.0 and 8.18.0. Defenders should prioritize verifying and applying patches, assessing exposure in systems using OAuth2 bearer tokens for HTTP(S) transfers, and monitoring for potential misuse of bearer tokens in cross-protocol [truncated]

MEDIUM curl CVE published 2026-01-08

CVE-2025-14017

CVE-2025-14017 is a medium-severity vulnerability in libcurl that affects multi-threaded LDAPS transfers. When using libcurl for multi-threaded LDAPS transfers, changing TLS options in one thread can inadvertently change them globally, potentially affecting other concurrently set up transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other th [truncated]

HIGH curl CVE published 2023-12-12

CVE-2024-2466

A vulnerability in libcurl's mbedTLS integration causes complete TLS certificate validation bypass when connecting to hosts specified as IP addresses. The flaw affects Siemens SINEC NMS and potentially other products using vulnerable libcurl builds with mbedTLS. CISA published advisory ICSA-24-319-04 on November 12, 2024, coordinating with Siemens' security advisory SSA-331112. The vulnerability is not li [truncated]

HIGH curl CVE published 2023-12-12

CVE-2024-2398

CVE-2024-2398 is a memory leak vulnerability in libcurl that occurs when HTTP/2 server push is enabled and the received headers exceed the maximum allowed limit of 1000. When libcurl aborts the server push under this condition, it fails to free all previously allocated headers, resulting in memory leakage. The error condition fails silently, making detection difficult for applications. The vulnerability w [truncated]