Vulnerabilidades en curl
74 resultadosAnálisis Vexday
O curl registra 64 vulnerabilidades na base Vexday, com 26 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob ataque confirmado (KEV zero), 8 atingem nível crítico, com dominância de falhas em validação de certificados (CWE-295), expondo usuários a riscos de man-in-the-middle. A recência das descobertas reforça a necessidade de acompanhar patches de forma rigorosa.
CVE-2026-11564CRITICALNative CA trust persistEPSS 0.4%CVE-2025-11563MEDIUMwcurl path traversal with percent-encoded slashesEPSS 0.4%CVE-2026-4873MEDIUMconnection reuse ignores TLS requirementEPSS 0.3%CVE-2026-9547HIGHSSH improper host validationEPSS 0.3%CVE-2026-8286HIGHwrong STARTTLS connection reuseEPSS 0.3%CVE-2026-9080HIGHUAF after pause in socket callbackEPSS 0.3%CVE-2026-6276HIGHstale custom cookie host causes cookie leakEPSS 0.3%CVE-2025-5025MEDIUMNo QUIC certificate pinning with wolfSSLEPSS 0.3%CVE-2025-4947MEDIUMQUIC certificate check skip with wolfSSLEPSS 0.3%CVE-2026-7009MEDIUMOCSP stapling bypass with Apple SecTrustEPSS 0.3%CVE-2026-9545HIGHexposing HTTP/3 early dataEPSS 0.3%CVE-2026-1965MEDIUMbad reuse of HTTP Negotiate connectionEPSS 0.3%CVE-2025-13034MEDIUMNo QUIC certificate pinning with GnuTLSEPSS 0.2%CVE-2025-14017MEDIUMbroken TLS options for threaded LDAPSEPSS 0.1%