Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-7141

28
FAUCET Score

CVE-2016-7141 describes a high-severity vulnerability in curl and libcurl versions prior to 7.50.2, specifically when built with NSS and libnsspem.so is available. This flaw allows remote attackers to hijack TLS connection authentication by reusing a previously loaded client certificate for a connection where none was explicitly set, affecting products like haxx leap, haxx libcurl, opensuse leap, and opensuse libcurl. The vulnerability has a CVSSv3 score of 7.5, indicating a high impact on integrity with low attack complexity and no user interaction required. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
42.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
<= 7.50.1CPE matchmatch criteria
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
8.40%
Probability of exploitation in next 30 days
EPSS Percentile
94.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0840 is in the 91st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

github_advisorypatch availablevia nvd_reference
View patch
jitsipatch availablevia llm_extracted
Fixed in: 7.50.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: curl-0:7.29.0-35.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-httpd-0:2.4.34-7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-nghttp2-0:1.7.1-7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-curl-0:7.61.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-httpd-0:2.4.34-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-nghttp2-0:1.7.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: httpd24-curl-0:7.61.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-curl-0:7.61.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-curl-0:7.61.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-nghttp2-0:1.7.1-7.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCS
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-curl-0:7.61.1-1.el6
View patch
sierra_wirelesspatch availablevia llm_extracted
Fixed in: 7.50.1
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Web Server 3Fixed in: curl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: mingw-virt-viewer
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: curl

Vendor Advisories (3)

sierra_wirelessllm-sierra_wireless-96f32eaa5be6df29HIGH

Incorrect reuse of client certificates

Sep 7, 2016
jitsillm-jitsi-747d836a4d2fe4adHIGH

Incorrect reuse of client certificates

Sep 7, 2016
redhatCVE-2016-7141Low

curl: Incorrect reuse of client certificates

Sep 5, 2016

References

lists.opensuse.org / opensuse-updates/2016-09/msg00094.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2575.html
rhn.redhat.com / errata/RHSA-2016-2957.html
access.redhat.com / errata/RHSA-2018:3558
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
curl.haxx.se / docs/adv_20160907.html
PatchVendor Advisory
github.com / curl/curl/commit/curl-7_50_2~32
Issue TrackingPatch
lists.debian.org / debian-lts-announce/2018/11/msg00005.html
security.gentoo.org / glsa/201701-47
oracle.com / technetwork/security-advisory/cpuoct2018-4428296.html
securityfocus.com / bid/92754
Third Party AdvisoryVDB Entry
securitytracker.com / id/1036739
Third Party AdvisoryVDB Entry