Vulnerabilidades em curl
74 resultadosAnálise Vexday
O curl registra 64 vulnerabilidades na base Vexday, com 26 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob ataque confirmado (KEV zero), 8 atingem nível crítico, com dominância de falhas em validação de certificados (CWE-295), expondo usuários a riscos de man-in-the-middle. A recência das descobertas reforça a necessidade de acompanhar patches de forma rigorosa.
CVE-2023-46219MEDIUMWhen saving HSTS data to an excessively long file name, curl could end up
removing all contents, making subsequent requests using that file EPSS 1.1%CVE-2024-0853MEDIUMOCSP verification bypass with TLS session reuseEPSS 1.1%CVE-2026-80231HIGHnative CA store conn reuseEPSS 0.9%CVE-2026-80229HIGHOpenSSL provider use-after-freeEPSS 0.9%CVE-2026-18924CRITICALHTTP/2 server push UAFEPSS 0.9%CVE-2024-6874LOWmacidn punycode buffer overreadEPSS 0.8%CVE-2026-3805HIGHuse after free in SMB connection reuseEPSS 0.7%CVE-2025-14819MEDIUMOpenSSL partial chain store policy bypassEPSS 0.7%CVE-2024-8096MEDIUMOCSP stapling bypass with GnuTLSEPSS 0.7%CVE-2026-6253MEDIUMproxy credentials leak over redirect-to proxyEPSS 0.7%CVE-2026-11352HIGHQUIC zero-length UDP datagrams busy-loopEPSS 0.7%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 0.7%CVE-2025-0167LOWnetrc and default credential leakEPSS 0.7%CVE-2026-80255HIGHsecure cookie attribute bypass with tabEPSS 0.7%CVE-2026-8925CRITICALSASL double-freeEPSS 0.7%CVE-2025-14524MEDIUMbearer token leak on cross-protocol redirectEPSS 0.7%CVE-2026-8924CRITICALtrailing dot domain super cookieEPSS 0.7%CVE-2026-13608HIGHOpenLDAP SASL authentication bypassEPSS 0.6%CVE-2026-5773HIGHwrong reuse of SMB connectionEPSS 0.6%CVE-2026-11586HIGHWS Auto-PONG memory exhaustionEPSS 0.6%