Haxx Vulnerabilities

Comprehensive security vulnerability database for Haxx products

Last updated: Mar 30, 2023
Total CVEs

3

Critical

1

With Exploits

6

Last 30 Days

0

Severity Distribution

Critical1
33%
High3
100%
Medium1
33%
Low1
33%
DescriptionVendor / ProductExploit Status
CVE-2023-275338.8

An attacker can exploit a vulnerability in curl to send malicious commands during TELNET communication, potentially allowing them to execute arbitrary code on the system. This can happen if an application using curl accepts user input without properly checking it, making it particularly risky for applications that rely on user-provided data.

haxxcurl
Exploit Available
almost 3 years agoMar 30, 2023
CVE-2022-435517.5

An attacker can trick curl into using an insecure HTTP connection instead of the intended secure HTTPS by manipulating the URL with special characters that confuse the software's security checks. This vulnerability occurs when the URL contains IDN characters that are converted to ASCII, allowing the attacker to bypass the HSTS protection that should enforce secure connections.

haxxcurl
Exploit Available
about 3 years agoDec 23, 2022
CVE-2022-429167.5

This vulnerability allows an attacker to trick curl into using an insecure HTTP connection instead of the intended secure HTTPS connection by manipulating the URL with special characters. This can happen when the URL includes international domain names that get converted to ASCII, making it possible for the attacker to bypass security checks designed to enforce HTTPS.

haxxcurl
Exploit Available
over 3 years agoOct 29, 2022

About Haxx Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Haxx products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.