Vulnerabilidades en curl
74 resultadosAnálisis Vexday
O curl registra 64 vulnerabilidades na base Vexday, com 26 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob ataque confirmado (KEV zero), 8 atingem nível crítico, com dominância de falhas em validação de certificados (CWE-295), expondo usuários a riscos de man-in-the-middle. A recência das descobertas reforça a necessidade de acompanhar patches de forma rigorosa.
CVE-2026-10536CRITICALHTTP/2 stream-dependency tree UAFEPSS 0.6%CVE-2026-9079CRITICALstale proxy password leakEPSS 0.6%CVE-2026-80230HIGHOpenSSL pinning bypassEPSS 0.6%CVE-2026-82209HIGHdomain-scoped PSL domain cookieEPSS 0.5%CVE-2025-15079MEDIUMlibssh global known_hosts overrideEPSS 0.5%CVE-2026-6429MEDIUMnetrc credential leak with reused proxy connectionEPSS 0.5%CVE-2026-8927CRITICALenv-set cross-proxy Digest auth state leakEPSS 0.5%CVE-2025-10148MEDIUMpredictable WebSocket maskEPSS 0.5%CVE-2026-9546HIGHsending old refererEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%CVE-2026-7168MEDIUMcross-proxy Digest auth state leakEPSS 0.5%CVE-2026-3783MEDIUMtoken leak with redirect and netrcEPSS 0.5%CVE-2026-8926CRITICALpassword leak with netrc and user in URLEPSS 0.4%CVE-2026-82208HIGHwolfSSL CA-cache hit overrides callbackEPSS 0.4%CVE-2026-5545MEDIUMwrong reuse of HTTP Negotiate connectionEPSS 0.4%CVE-2026-3784MEDIUMwrong proxy connection reuse with credentialsEPSS 0.4%CVE-2025-10966MEDIUMmissing SFTP host verification with wolfSSHEPSS 0.4%CVE-2026-12064HIGHproto-default skips SSH verificationEPSS 0.4%CVE-2026-8932HIGHincomplete mTLS config matching in conn reuseEPSS 0.4%CVE-2026-8458MEDIUMwrong reuse for different servicesEPSS 0.4%