curl
First CVE: Feb 3, 2024Active for: 2 years
57
CVEs Published
More CVEs Published than 61% of tracked CNAs
19.0
Avg CVEs / Year
More Avg CVEs / Year than 67% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by curl as a CNA, 100.0% affect products that curl develops as a vendor.
100.0%
Self-reported: 57Third-party: 0
Of all the CVEs published that affect products developed by curl, 83.8% are self-published by curl as a CNA.
83.8%
16.2%
Self-published: 57Published by other CNAs: 11
Trends Over Time
The number and severity of CVEs published by curl over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2024
2 years ago
Most Recent CVE
Jul 3, 2026
21 days ago
Top CVEs
All CVEs published by curl as a CNA, regardless of affected vendor or product.
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2398HIGH When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t | Mar 27, 2024 | 8.6 | 46 | NO | NO |
CVE-2026-9079CRITICAL libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers t | Jul 3, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-8925CRITICAL The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer t | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-10536CRITICAL A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequ | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-11856CRITICAL Successfully using libcurl to do a transfer to a specific HTTP origin
(`hostA`) with **Digest** authentication and then changing the origin to a
different one (`hostB`) for a secon | Jul 3, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-8932HIGH libcurl would reuse a previously created connection even when some mTLS config
related option had been changed that should have prohibited reuse.
libcurl keeps previously used con | Jul 3, 2026 | 7.5 | 39 | NO | NO |
CVE-2026-8927CRITICAL When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy configuration, libcurl fails to clear the proxy
authentication state between requests. S | Jul 3, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-8924CRITICAL A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to | Jul 3, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-11564CRITICAL libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle that first uses default native CA | Jul 3, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-8926CRITICAL When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could | Jul 3, 2026 | 9.1 | 38 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA57 CVEs
47%
32%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network56 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (73.7%)
High15 (26.3%)
Unknown0 (0.0%)
User Interaction
None46 (80.7%)
Unknown0 (0.0%)
Required11 (19.3%)
Privileges Required
Low8 (14.0%)
High0 (0.0%)
None49 (86.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (57 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by curl as a CNA.
Media Mentions
Media articles that mention a CVE ID published by curl as a CNA — matched by CVE ID, not by organization name.