Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Haxx

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 200
52.6
VTI Score
TOP TARGET

Haxx maintains curl and libcurl, a widely embedded transfer library and command-line tool that sit deep in the software supply chain and power HTTP/HTTPS operations across servers, appliances, applications, and development tools. Despite the narrow product portfolio, the vendor's prominence in the landscape stems from the ubiquity of these tools in both internet-facing and internal infrastructure, creating a broad downstream impact when vulnerabilities surface. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper certificate validation, sensitive information exposure, out-of-bounds reads, and memory-buffer handling flaws that reflect the parsing and cryptographic demands of a TLS-enabled transfer library. Defenders should prioritize curl and libcurl updates as widely applicable across diverse systems and treat exposed or embedded instances as a patching priority, since remediation often requires rebuilding downstream products that link the library. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
200
Total CVEs
More Total CVEs than 100% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Haxx over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (200 CVEs).

200 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38545CRITICAL
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the ad
Oct 18, 20239.876NONO
CVE-2011-3389MEDIUM
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b
Sep 6, 20114.371NOYES
CVE-2021-22901HIGH
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
CVE-2023-38039HIGH
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many
Sep 15, 20237.559NONO
CVE-2024-2398HIGH
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t
Mar 27, 20248.646NONO
CVE-2019-5436HIGH
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
May 28, 20197.846NONO
CVE-2013-0249HIGH
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authe
Mar 8, 20137.544NOYES
CVE-2026-9079CRITICAL
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers t
Jul 3, 20269.843NONO
CVE-2026-8925CRITICAL
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer t
Jul 3, 20269.842NONO
CVE-2026-10536CRITICAL
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequ
Jul 3, 20269.842NONO
View all 200 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products200 CVEs
41%
33%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (4.0%)
Network168 (84.0%)
Unknown23 (11.5%)
Physical1 (0.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low135 (67.5%)
High42 (21.0%)
Unknown23 (11.5%)
User Interaction
None150 (75.0%)
Unknown23 (11.5%)
Required27 (13.5%)
Privileges Required
Low20 (10.0%)
High0 (0.0%)
None157 (78.5%)
Unknown23 (11.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (200 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Haxx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Haxx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Haxx's Products

View all 7 CNAs →

Top CWEs