Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-22576

28
FAUCET Score

CVE-2022-22576 is an improper authentication vulnerability in curl versions 7.33.0 through 7.82.0, allowing OAUTH2-authenticated connections to be reused without proper credential verification for SASL-enabled protocols like SMTP, IMAP, POP3, and LDAP. This vulnerability affects products from vendors such as Brocade, Debian, Haxx, NetApp, and Splunk. With a CVSS score of 8.1 (HIGH), it presents a significant risk, allowing an attacker with low privileges to achieve high confidentiality and integrity impacts over the network with low attack complexity. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, there has been limited community discussion and media coverage, including a Siemens advisory.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.33.0, < 7.83.0CPE matchmatch criteria
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.04%
Probability of exploitation in next 30 days
EPSS Percentile
79.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0204 is in the 77th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: 18691-16820Fixed in: 7.76.0-9
microsoftpatch availablevia msrc
Product: cm1 curl 7.76.0-9 on CBL Mariner 1.0Fixed in: 7.76.0-9
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 7.76.0-9
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 7.76.0-9
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: curl-0:7.61.1-22.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: curl-0:7.76.1-14.el9_0.4
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 8.2.12, 9.0.6, 9.1.1
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: httpd24-curl

Vendor Advisories (5)

zimbrallm-zimbra-9542faa91a6d6884HIGH

August Third Party Package Updates in Splunk Universal Forwarder

Aug 30, 2023
microsoft2022-Jun/CVE-2022-22576

CVE-2022-22576

Jun 14, 2022
microsoft2022-May/CVE-2022-22576Important

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).

May 10, 2022
redhatCVE-2022-22576Moderate

curl: OAUTH2 bearer bypass in connection re-use

Apr 27, 2022
hikvisionllm-hikvision-b27ed5e72afb753bMEDIUM

OAUTH2 bearer bypass in connection reuse

Apr 27, 2022

References

hackerone.com / reports/1526328
ExploitIssue TrackingThird Party Advisory
lists.debian.org / debian-lts-announce/2022/08/msg00017.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202212-01
Third Party Advisory
security.netapp.com / advisory/ntap-20220609-0008
Third Party Advisory
debian.org / security/2022/dsa-5197
Third Party Advisory