Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-22901

60
FAUCET Score

CVE-2021-22901 is a use-after-free vulnerability in curl versions 7.75.0 through 7.76.1, affecting products from vendors like haxx, NetApp, Oracle, Siemens, and Splunk. A malicious server can exploit this flaw when a TLS 1.3 session ticket arrives over a connection, potentially leading to remote code execution in the client. This vulnerability is rated as High severity (CVSS 8.1) due to its network attack vector, high impact on confidentiality, integrity, and availability, and high attack complexity. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.75.0, <= 7.76.1CPE matchmatch criteria
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
1.11.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*
1.10.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
1.15.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
1.15.1CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
60.12%
Probability of exploitation in next 30 days
EPSS Percentile
99.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.6012 is in the 99th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (36)

github_advisorypatch availablevia nvd_reference
View patch
hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: 19009-16823Fixed in: 7.76.0-5
microsoftpatch availablevia msrc
Product: cbl2 curl 7.76.0-5 on CBL Mariner 2.0Fixed in: 7.76.0-5
microsoftpatch availablevia msrc
Product: 19039-16820Fixed in: 7.76.0-2
microsoftpatch availablevia msrc
Product: cm1 curl 7.76.0-2 on CBL Mariner 1.0Fixed in: 7.76.0-2
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-apr-util-0:1.6.1-82.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-brotli-0:1.0.6-40.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:7.77.0-2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-httpd-0:2.4.37-74.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-jansson-0:2.11-55.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-17.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_md-1:2.0.8-36.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_security-0:2.9.2-63.GA.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-37.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-1:1.1.1g-6.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-5.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-0:1-18.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-105.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-82.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.77.0-2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-74.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-jansson-0:2.11-55.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-17.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-36.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-63.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services Apache HTTP Server 2.4.37 SP8Fixed in: jbcs-httpd24-curl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-0:1-18.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-apr-0:1.6.3-105.el8jbcs
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 8.2.12, 9.0.6, 9.1.1

Vendor Advisories (4)

zimbrallm-zimbra-9542faa91a6d6884HIGH

August Third Party Package Updates in Splunk Universal Forwarder

Aug 30, 2023
microsoft2021-Jun/CVE-2021-22901Important

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory libcurl might even call a function pointer in the object making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct

Jun 8, 2021
redhatCVE-2021-22901Important

curl: Use-after-free in TLS session handling when using OpenSSL TLS backend

May 26, 2021
hikvisionllm-hikvision-b389f19af1aa5e0fHIGH

TLS session caching disaster

May 26, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
PatchThird Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-732250.pdf
Third Party Advisory
curl.se / docs/CVE-2021-22901.html
ExploitPatchVendor Advisory
github.com / curl/curl/commit/7f4a9a9b2a49547eae24d2e19bc5c346e9026479
PatchThird Party Advisory
hackerone.com / reports/1180380
ExploitIssue TrackingThird Party Advisory
security.netapp.com / advisory/ntap-20210723-0001
Third Party Advisory
security.netapp.com / advisory/ntap-20210727-0007
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory