4
1
10
4
Vulnerability Timeline
4 vulnerabilities discovered over time for Curl
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-3805 | 7.5 | This vulnerability allows an attacker to potentially execute arbitrary code on a system using curl when making a second SMB request to the same host, due to the software mistakenly using memory that has already been freed. To exploit this, the attacker must be able to send multiple SMB requests to the same server, which could happen in certain network configurations. | haxxcurl | Exploit Available | 28 days agoMar 11, 2026 |
| CVE-2023-27533 | 8.8 | An attacker can exploit a vulnerability in curl to send malicious commands during TELNET communication, potentially allowing them to execute arbitrary code on the system. This can happen if an application using curl accepts user input without properly checking it, making it particularly risky for applications that rely on user-provided data. | haxxcurl | Exploit Available | about 3 years agoMar 30, 2023 |
| CVE-2022-43551 | 7.5 | An attacker can trick curl into using an insecure HTTP connection instead of the intended secure HTTPS by manipulating the URL with special characters that confuse the software's security checks. This vulnerability occurs when the URL contains IDN characters that are converted to ASCII, allowing the attacker to bypass the HSTS protection that should enforce secure connections. | haxxcurl | Exploit Available | over 3 years agoDec 23, 2022 |
| CVE-2022-42916 | 7.5 | This vulnerability allows an attacker to trick curl into using an insecure HTTP connection instead of the intended secure HTTPS connection by manipulating the URL with special characters. This can happen when the URL includes international domain names that get converted to ASCII, making it possible for the attacker to bypass security checks designed to enforce HTTPS. | haxxcurl | Exploit Available | over 3 years agoOct 29, 2022 |
About Haxx Curl Security
This page provides comprehensive security vulnerability tracking for Haxx Curl. Our database includes all CVEs affecting this product, updated in real-time from official sources.
Each vulnerability listing includes detailed CVSS severity analysis, exploit availability status, AI-generated explanations, and direct links to official security patches and vendor advisories.
Security Recommendations
- • Always keep Curl updated to the latest version
- • Subscribe to security advisories from Haxx
- • Monitor this page for new vulnerabilities affecting your version
- • Prioritize patching critical and high severity issues immediately