Vulnerabilities in CURL
74 resultsVexday analysis
O CURL apresenta footprint reduzido na base Vexday com apenas 1 CVE registrada, atualmente sem exploração ativa conhecida (KEV=0). A vulnerabilidade identificada relaciona-se a validação inadequada de certificados (CWE-295), representando risco de confiança em conexões criptografadas, porém sem indicadores de ataque no período recente.
CVE-2023-46219MEDIUMWhen saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file EPSS 1.1%CVE-2024-0853MEDIUMOCSP verification bypass with TLS session reuseEPSS 1.1%CVE-2026-80231HIGHnative CA store conn reuseEPSS 0.9%CVE-2026-80229HIGHOpenSSL provider use-after-freeEPSS 0.9%CVE-2026-18924CRITICALHTTP/2 server push UAFEPSS 0.9%CVE-2024-6874LOWmacidn punycode buffer overreadEPSS 0.8%CVE-2026-3805HIGHuse after free in SMB connection reuseEPSS 0.7%CVE-2025-14819MEDIUMOpenSSL partial chain store policy bypassEPSS 0.7%CVE-2024-8096MEDIUMOCSP stapling bypass with GnuTLSEPSS 0.7%CVE-2026-6253MEDIUMproxy credentials leak over redirect-to proxyEPSS 0.7%CVE-2026-11352HIGHQUIC zero-length UDP datagrams busy-loopEPSS 0.7%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 0.7%CVE-2025-0167LOWnetrc and default credential leakEPSS 0.7%CVE-2026-80255HIGHsecure cookie attribute bypass with tabEPSS 0.7%CVE-2026-8925CRITICALSASL double-freeEPSS 0.7%CVE-2025-14524MEDIUMbearer token leak on cross-protocol redirectEPSS 0.7%CVE-2026-8924CRITICALtrailing dot domain super cookieEPSS 0.7%CVE-2026-13608HIGHOpenLDAP SASL authentication bypassEPSS 0.6%CVE-2026-5773HIGHwrong reuse of SMB connectionEPSS 0.6%CVE-2026-11586HIGHWS Auto-PONG memory exhaustionEPSS 0.6%