LibCURL_jll
JLSEC-2026-439High 7.5UpstreamWhen doing a second SMB request to the same host again, curl would wrongly use a data poi…JLSEC-2026-438Medium 6.5Upstreamcurl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, eve…JLSEC-2026-437Medium 5.3UpstreamWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a…JLSEC-2026-436Medium 6.5UpstreamNo summary availableJLSEC-2026-425Medium 4.6UpstreamURLs containing percent-encoded slashes (`/` or `\ `) can trick wcurl into saving the out…JLSEC-2026-431Low 3.1UpstreamWhen doing SSH-based transfers using either SCP or SFTP, and asked to do public key authe…JLSEC-2026-430Medium 5.3UpstreamWhen doing SSH-based transfers using either SCP or SFTP, and setting the `known_hosts` fi…JLSEC-2026-429Medium 5.3UpstreamWhen doing TLS related transfers with reused easy or multi handles and altering the...JLSEC-2026-428Medium 5.3UpstreamWhen an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a…JLSEC-2026-427Medium 6.3UpstreamWhen doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS opti…JLSEC-2026-426Medium 5.9UpstreamWhen using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the cur…JLSEC-2026-424Medium 4.3Upstreamcurl's code for managing SSH connections when SFTP was done using the wolfSSH powered bac…JLSEC-2026-435High 7.5Upstream1JLSEC-2026-423Medium 5.3Upstreamcurl's websocket code did not update the 32 bit mask pattern for each new outgoing frame …JLSEC-2026-434High 7.5UpstreamDue to a mistake in libcurl's WebSocket code, a malicious server can send a particularly …JLSEC-2026-433Medium 4.8Upstreamlibcurl supports *pinning* of the server certificate public key for HTTPS transfersJLSEC-2026-432Medium 6.5Upstreamlibcurl accidentally skips the certificate verification for QUIC connections when connect…JLSEC-2026-422High 7.3UpstreamWhen libcurl is asked to perform automatic gzip decompression of content-encoded HTTP res…JLSEC-2026-421High 7.0Upstreamlibcurl would wrongly close the same eventfd file descriptor twice when taking down a con…JLSEC-2026-420Low 3.4UpstreamWhen asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl …JLSEC-2026-413Low 3.4UpstreamWhen asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl…JLSEC-2026-419Medium 6.5UpstreamWhen curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent …JLSEC-2026-418Medium 6.5UpstreamWhen curl is told to use the Certificate Status Request TLS extension, often referred to …JLSEC-2025-38Medium 6.5Upstreamlibcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Gene…JLSEC-2025-37Medium 4.3Upstreamlibcurl's URL API function [`curl_url_get()`](https://curl.se/libcurl/c/curl_url_get.html…JLSEC-2025-36High 7.5Upstreamlibcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 str…JLSEC-2026-417Medium 6.5Upstreamlibcurl did not check the server certificate of TLS connections done to a host specified …JLSEC-2026-416High 8.6UpstreamWhen an application tells libcurl it wants to allow HTTP/2 server push, and the amount of…JLSEC-2026-415Medium 6.3Upstreamlibcurl skips the certificate verification for a QUIC connection under certain conditions…JLSEC-2026-414Low 3.5UpstreamWhen a protocol selection parameter option disables all protocols without adding any then…JLSEC-2026-412Medium 5.3Upstreamcurl inadvertently kept the SSL session ID for connections in its cache even when the ver…JLSEC-2026-411Medium 6.5UpstreamThis flaw allows a malicious HTTP server to set "super cookies" in curl that are then pas…JLSEC-2025-35Low 3.7UpstreamThis flaw allows an attacker to insert cookies at will into a running program using libcu…JLSEC-2025-34Critical 9.8UpstreamThis flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.JLSEC-2026-410Low 3.7UpstreamNo summary availableJLSEC-2026-409Medium 5.9UpstreamNo summary availableJLSEC-2026-408Medium 5.9UpstreamNo summary availableJLSEC-2026-407High 7.5UpstreamNo summary availableJLSEC-2025-33Medium 5.5UpstreamAn authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses …JLSEC-2025-32Medium 5.9UpstreamA double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separ…JLSEC-2025-30Medium 5.9UpstreamAn authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feat…JLSEC-2025-31Medium 5.9UpstreamAn authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reu…JLSEC-2026-406High 8.8UpstreamNo summary availableJLSEC-2026-405High 8.8UpstreamNo summary availableJLSEC-2026-404Medium 6.5UpstreamNo summary availableJLSEC-2026-403Medium 6.5UpstreamNo summary availableJLSEC-2026-402Critical 9.1UpstreamNo summary availableJLSEC-2026-401Medium 5.9UpstreamNo summary availableJLSEC-2026-400High 7.5UpstreamNo summary availableJLSEC-2026-396Critical 9.8UpstreamNo summary availableJLSEC-2026-398High 8.1UpstreamNo summary availableJLSEC-2026-399High 7.5UpstreamNo summary availableJLSEC-2026-397Low 3.7UpstreamNo summary availableJLSEC-2026-395Medium 5.9UpstreamNo summary availableJLSEC-2026-394Critical 9.8UpstreamNo summary availableJLSEC-2026-393Medium 6.5UpstreamNo summary availableJLSEC-2026-392Medium 4.3UpstreamNo summary availableJLSEC-2026-391High 7.5UpstreamNo summary availableJLSEC-2026-390High 7.5UpstreamNo summary availableJLSEC-2026-389High 7.5UpstreamNo summary availableJLSEC-2026-388Medium 6.5UpstreamNo summary availableJLSEC-2026-387High 7.5UpstreamNo summary availableJLSEC-2026-386Medium 5.7UpstreamNo summary availableJLSEC-2026-385High 8.1UpstreamNo summary availableJLSEC-2025-29Critical 9.1UpstreamWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumsta…JLSEC-2025-28Low 3.7Upstreamlibcurl keeps previously used connections in a connection pool for subsequenttransfers to…JLSEC-2025-27Low 3.7Upstreamcurl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS …JLSEC-2025-26Medium 5.3Upstreamcurl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Info…JLSEC-2025-25High 7.5Upstreamcurl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation …JLSEC-2025-24High 7.5Upstreamcurl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stac…JLSEC-2025-23High 7.5UpstreamDue to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connect…