Vulnerabilidades em CURL
74 resultadosAnálise Vexday
O CURL apresenta footprint reduzido na base Vexday com apenas 1 CVE registrada, atualmente sem exploração ativa conhecida (KEV=0). A vulnerabilidade identificada relaciona-se a validação inadequada de certificados (CWE-295), representando risco de confiança em conexões criptografadas, porém sem indicadores de ataque no período recente.
CVE-2026-10536CRITICALHTTP/2 stream-dependency tree UAFEPSS 0.6%CVE-2026-9079CRITICALstale proxy password leakEPSS 0.6%CVE-2026-80230HIGHOpenSSL pinning bypassEPSS 0.6%CVE-2026-82209HIGHdomain-scoped PSL domain cookieEPSS 0.5%CVE-2025-15079MEDIUMlibssh global known_hosts overrideEPSS 0.5%CVE-2026-6429MEDIUMnetrc credential leak with reused proxy connectionEPSS 0.5%CVE-2026-8927CRITICALenv-set cross-proxy Digest auth state leakEPSS 0.5%CVE-2025-10148MEDIUMpredictable WebSocket maskEPSS 0.5%CVE-2026-9546HIGHsending old refererEPSS 0.5%CVE-2025-15224LOWlibssh key passphrase bypass without agent setEPSS 0.5%CVE-2026-7168MEDIUMcross-proxy Digest auth state leakEPSS 0.5%CVE-2026-3783MEDIUMtoken leak with redirect and netrcEPSS 0.5%CVE-2026-8926CRITICALpassword leak with netrc and user in URLEPSS 0.4%CVE-2026-82208HIGHwolfSSL CA-cache hit overrides callbackEPSS 0.4%CVE-2026-5545MEDIUMwrong reuse of HTTP Negotiate connectionEPSS 0.4%CVE-2026-3784MEDIUMwrong proxy connection reuse with credentialsEPSS 0.4%CVE-2025-10966MEDIUMmissing SFTP host verification with wolfSSHEPSS 0.4%CVE-2026-12064HIGHproto-default skips SSH verificationEPSS 0.4%CVE-2026-8932HIGHincomplete mTLS config matching in conn reuseEPSS 0.4%CVE-2026-8458MEDIUMwrong reuse for different servicesEPSS 0.4%