Skip to main content

Vendor/product archive

haxx / curl CVEs

Beta · best-effort

161 CVEs tagged to haxx / curl27 Critical, 44 High, 76 Medium, 14 Low, 0 Unrated.

CVE-2022-30115

Published Jun 2, 2022

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2022-27780

Published Jun 2, 2022

The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-27779

Published Jun 2, 2022

libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie…

CVSS 5.3 · Medium

CVE-2020-8177

Published Dec 14, 2020

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS 7.8 · High
Showing 76-100 of 161 CVEsPage 4 of 7