Skip to content

Latest commit

 

History

History
372 lines (371 loc) · 48.1 KB

File metadata and controls

372 lines (371 loc) · 48.1 KB

Top reports from curl program at HackerOne:

  1. CVE-2021-22901: TLS session caching disaster to curl - 75 upvotes, $0
  2. CVE-2025-5399: WebSocket endless loop to curl - 57 upvotes, $0
  3. HTTP/3 Stream Dependency Cycle Exploit to curl - 56 upvotes, $0
  4. CVE-2020-8177: curl overwrite local file with -J to curl - 54 upvotes, $0
  5. CVE-2023-38545: socks5 heap buffer overflow to curl - 54 upvotes, $0
  6. Memory Leak in libcurl via Location Header Handling (CWE-770) to curl - 54 upvotes, $0
  7. CVE-2025-5025: No QUIC certificate pinning with wolfSSL to curl - 54 upvotes, $0
  8. CVE-2024-7264: ASN.1 date parser overread to curl - 53 upvotes, $0
  9. Buffer overflow in strcpy to curl - 52 upvotes, $0
  10. CVE-2020-8286: Inferior OCSP verification to curl - 51 upvotes, $0
  11. CVE-2024-9681: HSTS subdomain overwrites parent cache entry to curl - 49 upvotes, $0
  12. Hackers Attack Curl Vulnerability Accessing Sensitive Information to curl - 48 upvotes, $0
  13. Integer Underflow in src/var.c to curl - 46 upvotes, $0
  14. Buffer Overflow Vulnerability in strcpy() Leading to Remote Code Execution to curl - 45 upvotes, $0
  15. Curl_socketpair() fallback vulnerable to man-in-the-middle attack to curl - 45 upvotes, $0
  16. MQTT Protocol Packet Injection via Unchecked CONNACK Remaining Length to curl - 45 upvotes, $0
  17. Security check up to curl - 44 upvotes, $0
  18. CVE-2025-4947: QUIC certificate check skip with wolfSSL to curl - 43 upvotes, $0
  19. CVE-2025-10966: missing SFTP host verification with wolfSSH to curl - 43 upvotes, $0
  20. CRLF Injection in --proxy-header allows extra HTTP headers (CWE-93) to curl - 42 upvotes, $0
  21. wcurl Argument Injection via Unquoted Variable to curl - 42 upvotes, $0
  22. Credential leak on redirect due to improper state clearing when parsing macdef in netrc.c to curl - 41 upvotes, $0
  23. Buffer Overflow Risk in Curl_inet_ntop and inet_ntop4 to curl - 39 upvotes, $0
  24. Buffer Overflow Vulnerability in WebSocket Handling to curl - 38 upvotes, $0
  25. CVE-2024-8096: OCSP stapling bypass with GnuTLS to curl - 36 upvotes, $0
  26. CVE-2025-0167: netrc and default credential leak to curl - 36 upvotes, $0
  27. Sensitive information disclosure with malicious netrc file to curl - 36 upvotes, $0
  28. CVE-2025-9086: Out of bounds read for cookie path to curl - 36 upvotes, $0
  29. CVE-2024-6197: freeing stack buffer in utf8asn1str to curl - 34 upvotes, $0
  30. CVE-2024-2004: Usage of disabled protocol to curl - 33 upvotes, $0
  31. CVE-2024-11053: netrc + redirect credential leak to curl - 33 upvotes, $0
  32. on the implications of permitting procedural culling to curl - 33 upvotes, $0
  33. WebSocket Fragmentation DoS on Curl Client to curl - 32 upvotes, $0
  34. Missing Security Headers to curl - 32 upvotes, $0
  35. Unsanitized IPFS CID Allows SSRF Against Configured Gateway to curl - 32 upvotes, $0
  36. Arbitrary File Read via file:// Protocol in cURL to curl - 31 upvotes, $0
  37. testing hackerone functions to curl - 31 upvotes, $0
  38. CVE-2020-8284: trusting FTP PASV responses to curl - 30 upvotes, $0
  39. cookie is sent on redirect to curl - 30 upvotes, $0
  40. bypass of this Fixed #2437131 [ Inadequate Protocol Restriction Enforcement in curl ] to curl - 30 upvotes, $0
  41. Use-After-Free in OpenSSL Keylog Callback via SSL_get_ex_data() in libcurl to curl - 30 upvotes, $0
  42. Use After Free (that leads to arbitrary Write for some versions) to curl - 30 upvotes, $0
  43. libcurl: Host-Only Cookies Leak to Alternate IPv4 Forms to curl - 30 upvotes, $0
  44. OpenSSL backend: X509 peer certificate not freed in ossl_get_channel_binding causes per-request memory leak (DoS risk for long-lived clients) to curl - 30 upvotes, $0
  45. Apple SecTrust legacy path accepts untrusted certificates on pre-10.14 macOS/iOS when built with USE_APPLE_SECTRUST to curl - 30 upvotes, $0
  46. SSL options ISSUERCERT, EC_CURVES and CRLFILE silently ignored by non-OpenSSL backends to curl - 30 upvotes, $0
  47. Cross‑origin cookies leak and injection risk when using a custom Host header to curl - 30 upvotes, $0
  48. ("possible") UAF to curl - 29 upvotes, $0
  49. Heap‑based buffer overflow in curl -K <config_file> allows arbitrary write . to curl - 29 upvotes, $0
  50. CVE-2025-10148: predictable WebSocket mask to curl - 29 upvotes, $0
  51. Memory Leak to curl - 28 upvotes, $0
  52. Integer Overflow in schannel.c TLS Data Transmission to curl - 28 upvotes, $0
  53. curl leaks destination IP via glibc getaddrinfo() UDP connect, bypassing SOCKS5/Tor to curl - 28 upvotes, $0
  54. Out-of-bounds read in HTTP method handling causes undefined behavior and potential crash This is sharp, Gaurav. We’ve got a real memory-safety bug ins to curl - 28 upvotes, $0
  55. CVE-2023-46218: cookie mixed case PSL bypass to curl - 27 upvotes, $0
  56. CVE-2023-46219: HSTS long file name clears contents to curl - 27 upvotes, $0
  57. Double Free Vulnerability in libcurl Cookie Management (cookie.c) to curl - 27 upvotes, $0
  58. Stack use-after-scope in HTTP/3 POST request processing via CURLOPT_POSTFIELDS to curl - 27 upvotes, $0
  59. SMTP Command Injection Vulnerabilities in curl to curl - 27 upvotes, $0
  60. AWS SigV4 Signature Disclosure via Verbose Logging in libcurl to curl - 27 upvotes, $0
  61. Cookie Max-Age Integer Overflow Vulnerability to curl - 27 upvotes, $0
  62. CVE-2023-32001: fopen race condition to curl - 26 upvotes, $0
  63. NULL dereference when encoding DN of x509 certificate to curl - 26 upvotes, $0
  64. Use after free (read) in curl_multi_perform with DoH and Proxy options, and resolve timeouts to curl - 26 upvotes, $0
  65. Default Minimum TLS Version Set to TLS v1.0 (Cryptographic Weakness) to curl - 26 upvotes, $0
  66. Exposure of Private RSA Private Key in curl GitHub Repository to curl - 26 upvotes, $0
  67. Security Analysis Report: CURL Integer Overflow Vulnerability to curl - 26 upvotes, $0
  68. Timing Attack Vulnerability in curl Digest Authentication via Non-Constant-Time String Comparison to curl - 26 upvotes, $0
  69. HackerOne to curl - 26 upvotes, $0
  70. Arbitrary free in curl's config file parsing. to curl - 26 upvotes, $0
  71. A quiet New Year wish for security researchers to curl - 26 upvotes, $0
  72. CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine to curl - 25 upvotes, $0
  73. CVE-2024-6874: macidn punycode buffer overread to curl - 25 upvotes, $0
  74. Directory Traversal Vulnerability in cURL via Content-Disposition Header Processing to curl - 25 upvotes, $0
  75. CVE-2019-5435: An integer overflow found in /lib/urlapi.c to curl - 24 upvotes, $0
  76. CVE-2025-0665: eventfd double close to curl - 24 upvotes, $0
  77. curl ASSERTs when accessing an LDAP URL to curl - 24 upvotes, $0
  78. Vulnerability Report: Public Exposure of Security Audit File to curl - 24 upvotes, $0
  79. Heap-buffer-overflow (Out-of-Bounds Read) in DoH hostname encoding to curl - 24 upvotes, $0
  80. CVE-2024-0853: OCSP verification bypass with TLS session reuse to curl - 23 upvotes, $0
  81. Exploitable Format String Vulnerability in curl_mfprintf Function to curl - 23 upvotes, $0
  82. HTTP Request Smuggling Vulnerability Analysis - cURL Security Report to curl - 23 upvotes, $0
  83. Curl parse_connect_to_string Heap-Overread Leading to Denial of Service via CURLOPT_CONNECT_TO to curl - 23 upvotes, $0
  84. TOCTOU Race Condition in HTTP/2 Connection Reuse Leads to Certificate Validation Bypass to curl - 23 upvotes, $0
  85. Inconsistent URL Parsing in curl Leading to Potential SSRF and Access Control Bypass to curl - 22 upvotes, $0
  86. Hi Hacker to curl - 22 upvotes, $0
  87. [SFTP] TOCTOU Race Condition in Upload Resume Logic Leads to Arbitrary File Append to curl - 22 upvotes, $0
  88. HTTP/3 Protocol Smuggling and Header Injection via CRLF in QPACK value conversion to curl - 22 upvotes, $0
  89. CVE-2020-8169: Partial password leak over DNS on HTTP redirect to curl - 21 upvotes, $0
  90. Buffer overflow and affected url:-https://github.com/curl/curl/blob/master/docs/examples/hsts-preload.c to curl - 21 upvotes, $0
  91. Use of a Broken or Risky Cryptographic Algorithm (CWE-327) in libcurl to curl - 21 upvotes, $0
  92. HTTP Proxy Bypass via CURLOPT_CUSTOMREQUEST Verb Tunneling to curl - 21 upvotes, $0
  93. CRLF injection in libcurl's SMTP client via --mail-from and --mail-rcpt allows SMTP command smuggling to curl - 21 upvotes, $0
  94. Disk Space Exhaustion leading to a Denial of Service (DoS) to curl - 21 upvotes, $0
  95. OpenSSL HTTP/3 bogus CURLINFO_TLS_SSL_PTR to curl - 21 upvotes, $0
  96. Unbounded memory consumption via compressed HTTP responses (gzip/brotli/zstd) to curl - 21 upvotes, $0
  97. CVE-2023-28319: UAF in SSH sha256 fingerprint check to curl - 20 upvotes, $0
  98. HTTP/2 PUSH_PROMISE DoS to curl - 20 upvotes, $0
  99. Incorrect Type Conversion in interpreting IPv4-mapped IPv6 addresses and below curl results in indeterminate SSRF vulnerabilities. to curl - 20 upvotes, $0
  100. Memory leak of ftp (with proxy reuse) to curl - 20 upvotes, $0
  101. Uncontrolled File Write/Arbitrary File Creation to curl - 20 upvotes, $0
  102. GnuTLS CURLINFO_TLS_SESSION / CURLINFO_TLS_SSL_PTR type confusion to curl - 20 upvotes, $0
  103. Incorrect Parsing of IPv6 Zone ID in curl to curl - 20 upvotes, $0
  104. Title: Use-After-Free in cURL Test Suite via Improper Cleanup of Global Handle to curl - 20 upvotes, $0
  105. Protocol Smuggling / CRLF Injection via Gopher Protocol allows Arbitrary Command Injection to curl - 20 upvotes, $0
  106. HTTP/2 and HTTP/3 Header Injection in curl to curl - 20 upvotes, $0
  107. CVE-2022-27776: Auth/cookie leak on redirect to curl - 19 upvotes, $0
  108. When curl uses Schannel as TLS backend, it fails to enforce TLS 1.3 cipher suite selections correctly to curl - 19 upvotes, $0
  109. Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE Mismatch to curl - 19 upvotes, $0
  110. Insecure WebSocket Usage in curl Documentation and Examples (CWE-319: Cleartext Transmission of Sensitive Information) to curl - 19 upvotes, $0
  111. Account/Repository Takeover via Abandoned GitHub Username in curl's href_extractor.c to curl - 19 upvotes, $0
  112. ## Title Heap Use-After-Free Vulnerability in curl Leading to Potential Code Execution to curl - 19 upvotes, $0
  113. Confirmed Security Misconfigurations on curl.se (BREACH, Missing Security Headers, ETag Info Disclosure) to curl - 19 upvotes, $0
  114. Cookie exposure due to unexpected file permission change to curl - 19 upvotes, $0
  115. File URL UNC Path Access (Windows SSRF) to curl - 19 upvotes, $0
  116. Functional Regression in Digest Authentication: Failure to handle optional spaces and escaped quotes to curl - 19 upvotes, $0
  117. Cookie Replacement Use-After-Free Vulnerability to curl - 19 upvotes, $0
  118. Multiple Unsafe strcpy() Function Calls Leading to Potential Buffer Overflow Vulnerabilities in cURL 8.16.1-DEV to curl - 18 upvotes, $0
  119. Stack Buffer Overflow in cURL Cookie Parsing Leads to RCE to curl - 18 upvotes, $0
  120. SMTP Command Injection Vulnerability in libcurl 8.16.0 via RFC 3461 Suffix to curl - 18 upvotes, $0
  121. Integer Overflow to Heap Overflow in DoH Response Handling to curl - 18 upvotes, $0
  122. curl built with GnuTLS backend defaults to weak crypto parameters to curl - 18 upvotes, $0
  123. Path Traversal Bypass in file:// URLs Due to Incomplete URL-Encoded Path Normalization to curl - 18 upvotes, $0
  124. Proxy-Authorization header is leaked to origin server after redirect from proxied to direct connection to curl - 18 upvotes, $0
  125. PROTOCOL-LEVEL: Persistent UDP Amplification and Cache Poisoning via Alt-Svc Logic Flaw to curl - 18 upvotes, $0
  126. CVE-2025-15079: libssh global knownhost override to curl - 18 upvotes, $0
  127. CVE-2024-2466: TLS certificate check bypass with mbedTLS to curl - 17 upvotes, $0
  128. CVE-2025-0725: gzip integer overflow to curl - 17 upvotes, $0
  129. int overflow in krb5_read_data() leads to (possible) massive recv() write to curl - 17 upvotes, $0
  130. Race condition on global gss_context during SOCKS5 GSS-API negotiation in libcurl to curl - 17 upvotes, $0
  131. Infinite loop issue in the state machine of the curl project to curl - 17 upvotes, $0
  132. Certificate Hostname Validation Bypass via Leading Dot in Hostname to curl - 17 upvotes, $0
  133. Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 17 upvotes, $0
  134. HAProxy Connection Reuse leads to IP Spoofing and mTLS Context Smuggling to curl - 17 upvotes, $0
  135. Path Traversal in curl file:// Protocol Handler Allows Unauthorized File Access to curl - 17 upvotes, $0
  136. CVE-2025-14524: bearer token leak on cross-protocol redirect to curl - 17 upvotes, $0
  137. libcurl: Improper Authentication State Management on Cross-Protocol Redirects to curl - 17 upvotes, $0
  138. CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c to curl - 16 upvotes, $0
  139. CVE-2023-23916: HTTP multi-header compression denial of service to curl - 16 upvotes, $0
  140. Use-after-free when POST body buffer is freed before transfer to curl - 16 upvotes, $0
  141. Buffer Overflow in WebSocket Handshake (lib/ws.c:1287) to curl - 16 upvotes, $0
  142. Use of Deprecated strcpy() with User-Controlled Environment Variable in Memory Debug Initialization to curl - 16 upvotes, $0
  143. libcurl FTP path normalization flaw allows decoded %2e%2e → CWD .. and directory escape (Path Traversal, CWE-22) to curl - 16 upvotes, $0
  144. Cross‑Layer State Confusion in libcurl: Credential & Key‑Material Persistence Across Redirect / Connection Reuse Boundaries to curl - 16 upvotes, $0
  145. Telnet Suboption Buffer Pointer Underflow in lib/telnet.c leads to Out-of-Bounds Read to curl - 16 upvotes, $0
  146. CVE-2022-43552: HTTP Proxy deny use-after-free to curl - 15 upvotes, $0
  147. Format string vulnerability, curl_msnprintf() function to curl - 15 upvotes, $0
  148. Use after free (or assert triggered) with failed allocations in openssl to curl - 15 upvotes, $0
  149. Unsafe Global IFS Modification in OS400 Shell Script Enables Command Injection and Parsing Flaws (CWE-78/CWE-20) to curl - 15 upvotes, $0
  150. Incorrect sizeof() in Rustls Backend Memory Allocation to curl - 15 upvotes, $0
  151. Path Traversal in file:// protocol allows Arbitrary File Read to curl - 15 upvotes, $0
  152. Buffer Overflow in cURL Internal printf Function to curl - 15 upvotes, $0
  153. SMTP CRLF Injection & Protocol Desynchronization in libcurl to curl - 15 upvotes, $0
  154. CVE-2021-22897: schannel cipher selection surprise to curl - 14 upvotes, $0
  155. CVE-2021-22945: UAF and double-free in MQTT sending to curl - 14 upvotes, $0
  156. Stack-based Buffer Overflow in TELNET NEW_ENV Option Handling to curl - 14 upvotes, $0
  157. Elevation of Privileges (EoP) vulnerabilities related to the some easy_options on Windows to curl - 14 upvotes, $0
  158. curl --continue-at confusion to curl - 14 upvotes, $0
  159. access notes without permission to curl - 14 upvotes, $0
  160. Heap Buffer Overflow in TFTP to curl - 14 upvotes, $0
  161. MQTT Protocol Violation & Integer Overflow in libcurl to curl - 14 upvotes, $0
  162. CVE-2022-35252: control code in cookie denial of service to curl - 13 upvotes, $0
  163. Speculative Execution Side-Channel in curl to curl - 13 upvotes, $0
  164. Authorization Header Leak via --location-trusted in Curl to curl - 13 upvotes, $0
  165. curl doesn't hide credentials in /proc/XXX/cmdline provided via CLI arguments to curl - 13 upvotes, $0
  166. Title: Remote Code Execution (RCE) via Arbitrary Library Loading in --engine option to curl - 13 upvotes, $0
  167. Exposure of Hard-coded Private Keys and Credentials in curl Source Repository (CWE-321) to curl - 13 upvotes, $0
  168. Memory leak in Curl_auth_create_ntlm_type3_message to curl - 13 upvotes, $0
  169. CVE-2025-15224: libssh key passphrase bypass without agent set to curl - 13 upvotes, $0
  170. IMAP Protocol Desynchronization and Response Smuggling via Naive Literal Parsing to curl - 13 upvotes, $0
  171. CVE-2023-27537: HSTS double-free to curl - 12 upvotes, $0
  172. CVE-2024-2398: HTTP/2 push headers memory-leak to curl - 12 upvotes, $0
  173. Unicode-to-ASCII conversion on Windows can lead to argument injection and more to curl - 12 upvotes, $0
  174. OS Command Injection in scripts/firefox-db2pem.sh via untrusted certificate nicknames to curl - 12 upvotes, $0
  175. Missing enforcement of SFTP quote syntax can lead to operation on wrong object to curl - 12 upvotes, $0
  176. CURLX_SET_BINMODE(NULL) can call fileno(NULL) and cause undefined behavior / crash to curl - 12 upvotes, $0
  177. Unsafe use of strcpy in Curl_ldap_err2string (packages/OS400/os400sys.c) — stack-buffer-overflow (PoC + ASan) to curl - 12 upvotes, $0
  178. runs javascript on powershell when it shouldnt to curl - 12 upvotes, $0
  179. Stack Buffer Overflow in cURL wolfSSL Backend (lib/vtls/wolfssl.c) to curl - 12 upvotes, $0
  180. Denial of Service (DoS) vulnerability in dedotdotify() URL path normalization to curl - 12 upvotes, $0
  181. Security hardening: missing integer overflow check in curl_load_library() to curl - 12 upvotes, $0
  182. Alt-Svc bypasses credential leak protection (CVE-2018-1000007) to curl - 12 upvotes, $0
  183. CVE-2020-8231: Connect-only connections can use the wrong connection to curl - 11 upvotes, $0
  184. CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize to curl - 11 upvotes, $0
  185. CVE-2022-27778: curl removes wrong file on error to curl - 11 upvotes, $0
  186. CVE-2022-32208: FTP-KRB bad message verification to curl - 11 upvotes, $0
  187. CVE-2024-2379: QUIC certificate check bypass with wolfSSL to curl - 11 upvotes, $0
  188. curl allows SSH connection even if host is not in known_hosts to curl - 11 upvotes, $0
  189. Failure to strip Proxy-Authorization header on change in origin to curl - 11 upvotes, $0
  190. Stack Buffer Overflow in curl's OpenSSL Provider Handling to curl - 11 upvotes, $0
  191. Buffer Overflow in curl MQTT Test Server (tests/server/mqttd.c) via Malicious CONNECT Packet to curl - 11 upvotes, $0
  192. HTTP/2 CONTINUATION Flood Vulnerability to curl - 11 upvotes, $0
  193. Information Disclosure at : https://curl.se/.mailmap to curl - 11 upvotes, $0
  194. Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash to curl - 11 upvotes, $0
  195. A logic error in detect_proxy caused truncation of environment variable names for long protocol schemes. to curl - 11 upvotes, $0
  196. Public-suffix cookie injection when libpsl is disabled to curl - 11 upvotes, $0
  197. Integer Overflow in curl_easy_escape() may lead to heap buffer overflow and stack memory disclosure on 32-bit platforms to curl - 11 upvotes, $0
  198. SMB access smuggling via FILE URL on Windows to curl - 10 upvotes, $0
  199. CVE-2021-22946: Protocol downgrade required TLS bypassed to curl - 10 upvotes, $0
  200. Heap Buffer Overflow in libcurl curl_slist_append via Unterminated String to curl - 10 upvotes, $0
  201. curl -OJ allows creating custom .curlrc file which allows exfiltrating private data, among other things to curl - 10 upvotes, $0
  202. arbitrary file read via file:// path traversal with --path-as-is to curl - 10 upvotes, $0
  203. Git repository found to curl - 10 upvotes, $0
  204. information disclosure to curl - 10 upvotes, $0
  205. Path Traversal in SFTP QUOTE command leads to Arbitrary File Write and potential RCE to curl - 10 upvotes, $0
  206. curl’s persistence files inherit world-readable/writable perms from umask, leaking and tampering with cookies/HSTS/Alt-Svc caches to curl - 10 upvotes, $0
  207. Logical Flaw in curl_url_set Leads to Inconsistent Query Parameter Encoding to curl - 10 upvotes, $0
  208. SMTP CRLF Command Injection in CURLOPT_MAIL_FROM and CURLOPT_MAIL_RCPT to curl - 10 upvotes, $0
  209. Silent TLS Trust Model Hijacking via CURL_CA_BUNDLE Environment Variable Leads to MITM to curl - 10 upvotes, $0
  210. libcurl WebSocket handshake accepts any Sec-WebSocket-Accept to curl - 10 upvotes, $0
  211. MQTT: Missing upper bound on incoming Remaining Length allows server-controlled long wait to curl - 10 upvotes, $0
  212. Directory listing vulnerability is disclosing names and emails, widespread (thousands of records, publicly accessible without auth) to curl - 10 upvotes, $0
  213. CVE-2022-27780: percent-encoded path separator in URL host to curl - 9 upvotes, $0
  214. Cache purge requests are not authenticated to curl - 9 upvotes, $0
  215. Memory leak from doh_write_cb to curl - 9 upvotes, $0
  216. [High] MITM via Insecure CA Path Handling in cURL (--capath, CURLOPT_CAPATH) (CWE-494: Download of Code Without Integrity Check) to curl - 9 upvotes, $0
  217. curl_easy_header runs at O(N) or worse and can be abused to use minute(s) of CPU time to curl - 9 upvotes, $0
  218. Heap buffer overflow vulnerability in conncache.c: incorrect use of pointer arrays resulting in out-of-bounds memory writes. to curl - 9 upvotes, $0
  219. Disclosure of email addresses to curl - 9 upvotes, $0
  220. Vulnerability Report: Local File Disclosure via file:// Protocol in cURL to curl - 9 upvotes, $0
  221. Use of Deprecated strcpy() with Fixed-Size Buffers in Progress Time Formatting to curl - 9 upvotes, $0
  222. libcurl MQTT PUBLISH length overflow (heap overflow) to curl - 9 upvotes, $0
  223. Arbitrary Configuration File Inclusion: via External Control of File Name or Path to curl - 9 upvotes, $0
  224. Heap Buffer Over-Read via Malicious SMB Server READ_ANDX Response to curl - 9 upvotes, $0
  225. CRLF Injection in Gopher Protocol (lib/gopher.c) to curl - 9 upvotes, $0
  226. HTTP Request Smuggling and SSRF via CRLF Injection in Curl_add_custom_headers to curl - 9 upvotes, $0
  227. Arbitrary File Read via Unsanitized curl Usage Results in Sensitive File Exposure to curl - 8 upvotes, $0
  228. Free of uninitialized pointer in doh_decode_rdata_name() to curl - 8 upvotes, $0
  229. Path Traversal Vulnerability in curl via Unsanitized IPFS_PATH Environment Variable to curl - 8 upvotes, $0
  230. Buffer Overflow in curl's Rustls Backend to curl - 8 upvotes, $0
  231. Double free caused by mqtt_doing() to curl - 8 upvotes, $0
  232. Potential XSS vector in curl via unsanitized URL parameter handling to curl - 8 upvotes, $0
  233. Arbitrary File Deletion Vulnerability in curl Source Code via os.unlink() to curl - 8 upvotes, $0
  234. SOCKS5 Heap Buffer Overflow via Malicious HTTP Redirect with Oversized Hostname to curl - 8 upvotes, $0
  235. libcurl MQTT CURLOPT_POSTFIELDSIZE_LARGE overflow leads to immediate DoS to curl - 8 upvotes, $0
  236. SMTP CRLF Injection in curl/libcurl via MAIL FROM/RCPT TO parameters to curl - 8 upvotes, $0
  237. Command Injection - CRITICISM to curl - 8 upvotes, $0
  238. Hash exposed in public repository to curl - 8 upvotes, $0
  239. Malicious server forces .curlrc creation via curl -OJ leading to local file exfiltration to curl - 8 upvotes, $0
  240. Off-by-One Buffer Overflow in SMB Path Handler to curl - 8 upvotes, $0
  241. Terminal Output Not Great to curl - 8 upvotes, $0
  242. Curl Alt-Svc Parser Stack Buffer Overflow to curl - 8 upvotes, $0
  243. Heap Overflow in cURL AmigaOS Socket Implementation to curl - 8 upvotes, $0
  244. Heap Buffer Over-read in lib/http2.c (on_header) handling PUSH_PROMISE frames to curl - 8 upvotes, $0
  245. WebSocket Logic Error: Control Frame (PING/PONG) Starvation causes Connection Drop (DoS) during large transfers to curl - 8 upvotes, $0
  246. Stack Buffer Overflow in mprintf.c formatting function (fallback path) to curl - 8 upvotes, $0
  247. State Isolation Failure in Multiplexed Connections (Shared Auth Context) to curl - 8 upvotes, $0
  248. Use-After-Free in curl_easy_nextheader when reusing header handle across requests to curl - 8 upvotes, $0
  249. Digest Authentication Header Injection to curl - 8 upvotes, $0
  250. CVE-2021-22890: TLS 1.3 session ticket proxy host mixup to curl - 7 upvotes, $0
  251. CVE-2021-22898: TELNET stack contents disclosure to curl - 7 upvotes, $0
  252. CVE-2021-22947: STARTTLS protocol injection via MITM to curl - 7 upvotes, $0
  253. CVE-2022-27774: Credential leak on redirect to curl - 7 upvotes, $0
  254. CVE-2022-27775: Bad local IPv6 connection reuse to curl - 7 upvotes, $0
  255. CVE-2022-30115: HSTS bypass via trailing dot to curl - 7 upvotes, $0
  256. CVE-2022-35260: .netrc parser out-of-bounds access to curl - 7 upvotes, $0
  257. CVE-2022-42915: HTTP proxy double-free to curl - 7 upvotes, $0
  258. CVE-2022-43551: Another HSTS bypass via IDN to curl - 7 upvotes, $0
  259. curl file writing susceptible to symlink attacks to curl - 7 upvotes, $0
  260. CVE-2023-23915: HSTS amnesia with --parallel to curl - 7 upvotes, $0
  261. Incorrect Encoding Conversion in hostname results in indeterminate SSRF vulnerabilities to curl - 7 upvotes, $0
  262. Improper Restriction of Authentication Attempts in cURL to curl - 7 upvotes, $0
  263. [High] Arbitrary File Write via Path Traversal in cURL CLI (-o, --output) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) to curl - 7 upvotes, $0
  264. Buffer over-read,, Missing NUL termination in addvariable() causes undefined behavior to curl - 7 upvotes, $0
  265. Certificate Pinning Bypass with wolfSSL backend over HTTP/3 to curl - 7 upvotes, $0
  266. Integer-underflow leads to heap over-read in TFTP implementation to curl - 7 upvotes, $0
  267. Integer Overflow in curl_multi_get_handles() Leading to Heap Buffer Overflow to curl - 7 upvotes, $0
  268. Github wikis are editable by anyone #Githubwikistakeover to curl - 6 upvotes, $0
  269. CVE-2019-5481: krb5: double-free in read_data() after realloc() fail to curl - 6 upvotes, $0
  270. --libcurl code injection via trigraphs to curl - 6 upvotes, $0
  271. CVE-2022-22576: OAUTH2 bearer bypass in connection re-use to curl - 6 upvotes, $0
  272. CVE-2022-27782: TLS and SSH connection too eager reuse to curl - 6 upvotes, $0
  273. CVE-2022-32207: Unpreserved file permissions to curl - 6 upvotes, $0
  274. CVE-2023-23914: curl HSTS ignored on multiple requests to curl - 6 upvotes, $0
  275. CVE-2023-28320: siglongjmp race condition to curl - 6 upvotes, $0
  276. Denial of Service in curl Request - HTTP headers eat all memory to curl - 6 upvotes, $0
  277. -H with space prefix leads to previous header injection when used with --proxy to curl - 6 upvotes, $0
  278. netrc crlf injection to curl - 6 upvotes, $0
  279. SMTP Protocol Injection via CRLF in CURLOPT_MAIL_FROM leading to Email Spoofing to curl - 6 upvotes, $0
  280. inconsistently Rejection Logic in file:// URLs with Authority to curl - 6 upvotes, $0
  281. Gopher Protocol Command Injection (SSRF Smuggling) to curl - 6 upvotes, $0
  282. Able to bypass HSTS using trailing dot to curl - 6 upvotes, $0
  283. Active Mixed Content over HTTPS to curl - 5 upvotes, $0
  284. SSRF via maliciously crafted URL due to host confusion to curl - 5 upvotes, $0
  285. CVE-2021-22876: Automatic referer leaks credentials to curl - 5 upvotes, $0
  286. CVE-2021-22922: Wrong content via metalink not discarded to curl - 5 upvotes, $0
  287. CVE-2021-22926: CURLOPT_SSLCERT mixup with Secure Transport to curl - 5 upvotes, $0
  288. CVE-2021-22924: Bad connection reuse due to flawed path name checks to curl - 5 upvotes, $0
  289. Remote memory disclosure vulnerability in libcurl on 64 Bit Windows to curl - 5 upvotes, $0
  290. CVE-2022-27779: cookie for trailing dot TLD to curl - 5 upvotes, $0
  291. Credential leak on redirect to curl - 5 upvotes, $0
  292. CVE-2022-27781: CERTINFO never-ending busy-loop to curl - 5 upvotes, $0
  293. TLS Cipher Misconfiguration in HTTP/3/QUIC Support to curl - 5 upvotes, $0
  294. curl mishandles %0c%0b sequences in HTTP responses leading to CRLF confusions, Headers and Cookies Injection to curl - 5 upvotes, $0
  295. Double free in tool_ssls_load() to curl - 5 upvotes, $0
  296. CRLF Injection / Protocol Smuggling in libcurl via CURLOPT_USERNAME (IMAP) to curl - 5 upvotes, $0
  297. CRLF Injection in HTTP header values allows arbitrary header injection to curl - 5 upvotes, $0
  298. Heap Out-of-Bounds Read in lib/http2.c via Malformed PUSH_PROMISE Headers to curl - 5 upvotes, $0
  299. integer Overflow in MQTT Protocol Handling Allows Bypassing Message Size Limit to curl - 5 upvotes, $0
  300. RTSP RTP Interleaved Parser Assertion Failure (Zero-Length RTP Payload) to curl - 5 upvotes, $0
  301. Signed integer overflow in tool_progress_cb() to curl - 4 upvotes, $0
  302. Invalid write (or double free) triggers curl command line tool crash to curl - 4 upvotes, $0
  303. Integer overflows in tool_operate.c at line 1541 to curl - 4 upvotes, $0
  304. CVE-2021-22923: Metalink download sends credentials to curl - 4 upvotes, $0
  305. CURLOPT_SSH_HOST_PUBLIC_KEY_MD5 bypass if string not 32 chars to curl - 4 upvotes, $0
  306. Memory leak in CURLOPT_XOAUTH2_BEARER to curl - 4 upvotes, $0
  307. error parse uri path in curl to curl - 4 upvotes, $0
  308. CVE-2022-32206: HTTP compression denial of service to curl - 4 upvotes, $0
  309. CVE-2022-32205: Set-Cookie denial of service to curl - 4 upvotes, $0
  310. libssh backend CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 validation bypass to curl - 4 upvotes, $0
  311. CVE-2023-27533: Telnet option IAC injection to curl - 4 upvotes, $0
  312. CVE-2023-27535: FTP too eager connection reuse to curl - 4 upvotes, $0
  313. CVE-2023-27536: GSS delegation too eager connection re-use to curl - 4 upvotes, $0
  314. CVE-2023-27538: SSH connection too eager reuse still to curl - 4 upvotes, $0
  315. OS Command Injection (subprocess Module Usage) to curl - 4 upvotes, $0
  316. Heap buffer overflow in Curl_ipv4_resolve_r due to incorrect buffer alignment and size calculation on AmigaOS to curl - 4 upvotes, $0
  317. MQTT: unsigned integer underflow bypasses MAX_MQTT_MESSAGE_SIZE check to curl - 4 upvotes, $0
  318. curl overwrites local file with -J option if file non-readable, but file writable. to curl - 3 upvotes, $0
  319. CVE-2020-8285: FTP wildcard stack overflow to curl - 3 upvotes, $0
  320. Abusing URL Parsers by long schema name to curl - 3 upvotes, $0
  321. Poll loop/hang on incomplete HTTP header to curl - 3 upvotes, $0
  322. Integer overflow in the source code tool_cb_prg.c to curl - 3 upvotes, $0
  323. CVE-2021-22925: TELNET stack contents disclosure again to curl - 3 upvotes, $0
  324. Denial of Service vulnerability in curl when parsing MQTT server response to curl - 3 upvotes, $0
  325. Credential leak when use two url to curl - 3 upvotes, $0
  326. CVE-2022-32221: POST following PUT confusion to curl - 3 upvotes, $0
  327. CVE-2023-27534: SFTP path ~ resolving discrepancy to curl - 3 upvotes, $0
  328. CVE-2023-28322: more POST-after-PUT confusion to curl - 3 upvotes, $0
  329. Integer Overflow Risk in HTTP/2 Proxy Window Size Calculations to curl - 3 upvotes, $0
  330. Curl Telnet Handler Buffer Overflow to curl - 3 upvotes, $0
  331. Heap Buffer Overflow (READ of size 1) in ourWriteOut to curl - 2 upvotes, $0
  332. Libcurl ocasionally sends HTTPS traffic to port 443 rather than specified port 8080 to curl - 2 upvotes, $0
  333. Integer overlow in "header_append" function to curl - 2 upvotes, $0
  334. curl on Windows can be forced to execute code via OpenSSL environment variables to curl - 2 upvotes, $0
  335. Proxy-Authorization header carried to a new host on a redirect to curl - 2 upvotes, $0
  336. Binary output bypass to curl - 2 upvotes, $0
  337. CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 comparison disaster to curl - 2 upvotes, $0
  338. Certificate authentication re-use on redirect to curl - 2 upvotes, $0
  339. Cookie injection from non-secure context to curl - 2 upvotes, $0
  340. Heap overflow via HTTP/2 PUSH_PROMISE to curl - 2 upvotes, $0
  341. CVE-2022-42916: HSTS bypass via IDN to curl - 2 upvotes, $0
  342. CVE-2023-28321: IDN wildcard match to curl - 2 upvotes, $0
  343. Insecure Frame (External) to curl - 1 upvotes, $0
  344. Parallel upload hangs curl if upload file not found to curl - 1 upvotes, $0
  345. libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823 to curl - 1 upvotes, $0
  346. Race condition with CURL_LOCK_DATA_CONNECT can cause connections to be used at the same time to curl - 1 upvotes, $0
  347. Division by zero if terminal width is 2 to curl - 1 upvotes, $0
  348. Unexpected access to process open files via file:///proc/self/fd/n to curl - 1 upvotes, $0
  349. use after free in cookie.c to curl - 1 upvotes, $0
  350. Potential invocation of qsort on uninitialized memory during cookie save to curl - 1 upvotes, $0
  351. Resource leak when using a normal site as DOH server to curl - 1 upvotes, $0
  352. Buffer write overflow when forming dns over http request to curl - 1 upvotes, $0
  353. Integer overflow at line 1603 in the src/operator.c file to curl - 1 upvotes, $0
  354. huge COLUMNS causes progress-bar to buffer overflow to curl - 1 upvotes, $0
  355. Inadequate Cryptographic Key Size and Insecure Cryptographic Mode. File Name :- curl_ntlm_core.c to curl - 1 upvotes, $0
  356. Occasional use-after-free in multi_done() libcurl-7.81.0 to curl - 1 upvotes, $0
  357. Use of Unsafe function || Strcpy to curl - 1 upvotes, $0
  358. curl proceeds with unsafe connections when -K file can't be read to curl - 1 upvotes, $0
  359. KRB-FTP: Security level downgrade to curl - 1 upvotes, $0
  360. curl "globbing" can lead to denial of service attacks to curl - 1 upvotes, $0
  361. Port and service scanning on localhost due to improper URL validation. to curl - 0 upvotes, $0
  362. Data race conditions reported by helgrind when performing parallel DNS queries in libcurl to curl - 0 upvotes, $0
  363. Only OpenSSL handles a CRL when passed in via CApath to curl - 0 upvotes, $0
  364. curl successfully matches IP address literal in URL against IP address literal in certificate Common Name to curl - 0 upvotes, $0
  365. Curl_auth_create_plain_message integer overflow leads to heap buffer overflow to curl - 0 upvotes, $0
  366. curl still vulnerable to SMB access smuggling via FILE URL on Windows to curl - 0 upvotes, $0
  367. Incorrect IPv6 literal parsing leads to validated connection to unexpected https server. to curl - 0 upvotes, $0
  368. Double-free of trailers_buf' on Curl_http_compile_trailers()` failure to curl - 0 upvotes, $0
  369. match to curl - 0 upvotes, $0
  370. Integer overflows in unescape_word() to curl - 0 upvotes, $0