Vulnerabilities in CURL
74 resultsVexday analysis
O CURL apresenta footprint reduzido na base Vexday com apenas 1 CVE registrada, atualmente sem exploração ativa conhecida (KEV=0). A vulnerabilidade identificada relaciona-se a validação inadequada de certificados (CWE-295), representando risco de confiança em conexões criptografadas, porém sem indicadores de ataque no período recente.
CVE-2026-11564CRITICALNative CA trust persistEPSS 0.4%CVE-2025-11563MEDIUMwcurl path traversal with percent-encoded slashesEPSS 0.4%CVE-2026-4873MEDIUMconnection reuse ignores TLS requirementEPSS 0.3%CVE-2026-9547HIGHSSH improper host validationEPSS 0.3%CVE-2026-8286HIGHwrong STARTTLS connection reuseEPSS 0.3%CVE-2026-9080HIGHUAF after pause in socket callbackEPSS 0.3%CVE-2026-6276HIGHstale custom cookie host causes cookie leakEPSS 0.3%CVE-2025-5025MEDIUMNo QUIC certificate pinning with wolfSSLEPSS 0.3%CVE-2025-4947MEDIUMQUIC certificate check skip with wolfSSLEPSS 0.3%CVE-2026-7009MEDIUMOCSP stapling bypass with Apple SecTrustEPSS 0.3%CVE-2026-9545HIGHexposing HTTP/3 early dataEPSS 0.3%CVE-2026-1965MEDIUMbad reuse of HTTP Negotiate connectionEPSS 0.3%CVE-2025-13034MEDIUMNo QUIC certificate pinning with GnuTLSEPSS 0.2%CVE-2025-14017MEDIUMbroken TLS options for threaded LDAPSEPSS 0.1%