Haxx maintains curl and libcurl, a widely embedded transfer library and command-line tool that sit deep in the software supply chain and power HTTP/HTTPS operations across servers, appliances, applications, and development tools. Despite the narrow product portfolio, the vendor's prominence in the landscape stems from the ubiquity of these tools in both internet-facing and internal infrastructure, creating a broad downstream impact when vulnerabilities surface. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper certificate validation, sensitive information exposure, out-of-bounds reads, and memory-buffer handling flaws that reflect the parsing and cryptographic demands of a TLS-enabled transfer library. Defenders should prioritize curl and libcurl updates as widely applicable across diverse systems and treat exposed or embedded instances as a patching priority, since remediation often requires rebuilding downstream products that link the library. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haxx over time
Signals from CVEs in this vendor scope (200 CVEs).
200 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38545CRITICAL This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the ad | Oct 18, 2023 | 9.8 | 76 | NO | NO |
CVE-2011-3389MEDIUM The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b | Sep 6, 2011 | 4.3 | 71 | NO | YES |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2023-38039HIGH When curl retrieves an HTTP response, it stores the incoming headers so that
they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many | Sep 15, 2023 | 7.5 | 59 | NO | NO |
CVE-2024-2398HIGH When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t | Mar 27, 2024 | 8.6 | 46 | NO | NO |
CVE-2019-5436HIGH A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | May 28, 2019 | 7.8 | 46 | NO | NO |
CVE-2013-0249HIGH Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authe | Mar 8, 2013 | 7.5 | 44 | NO | YES |
CVE-2026-9079CRITICAL libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers t | Jul 3, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-8925CRITICAL The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer t | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-10536CRITICAL A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequ | Jul 3, 2026 | 9.8 | 42 | NO | NO |
Signals from CVEs in this vendor scope (200 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haxx.
Media articles that mention a CVE ID that affects a product developed by Haxx — matched by CVE ID, not by vendor name.