Curl
Vendor:
First CVE: May 2, 2005 · Active for 21 years
199
Total CVEs
More Total CVEs than 99% of tracked products
12.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Curl over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jul 3, 2026
25 days ago
CVE Severity & Scoring
Curl199 CVEs
40%
33%
20%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (4.0%)
Network167 (83.9%)
Unknown23 (11.6%)
Physical1 (0.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low134 (67.3%)
High42 (21.1%)
Unknown23 (11.6%)
User Interaction
None150 (75.4%)
Unknown23 (11.6%)
Required26 (13.1%)
Privileges Required
Low19 (9.5%)
High0 (0.0%)
None157 (78.9%)
Unknown23 (11.6%)
Top CVEs
Signals from CVEs in this product scope (199 CVEs).
199 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38545CRITICAL This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the ad | Oct 18, 2023 | 9.8 | 76 | NO | NO |
CVE-2011-3389MEDIUM The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b | Sep 6, 2011 | 4.3 | 71 | NO | YES |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2023-38039HIGH When curl retrieves an HTTP response, it stores the incoming headers so that
they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many | Sep 15, 2023 | 7.5 | 59 | NO | NO |
CVE-2024-2398HIGH When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t | Mar 27, 2024 | 8.6 | 46 | NO | NO |
CVE-2019-5436HIGH A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | May 28, 2019 | 7.8 | 46 | NO | NO |
CVE-2013-0249HIGH Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authe | Mar 8, 2013 | 7.5 | 44 | NO | YES |
CVE-2026-9079CRITICAL libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers t | Jul 3, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-8925CRITICAL The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer t | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-10536CRITICAL A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequ | Jul 3, 2026 | 9.8 | 42 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (199 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.5% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (199 CVEs).
Media Mentions
Signals from CVEs in this product scope (199 CVEs).
Top CNAs Publishing CVEs For Curl
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.8.0 | 1 | 4.3 | 0.8% | 0 | 0 |
| 8.6.0 | 1 | 6.3 | 1.7% | 0 | 0 |
| 8.5.0 | 1 | 5.3 | 1.1% | 0 | 0 |
| 8.11.1 | 1 | 7.0 | 1.3% | 0 | 0 |
| 7.9.8 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.7 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.6 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.5 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.4 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.3 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.2 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9.1 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.9 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.88.1 | 1 | 5.9 | 1.9% | 0 | 0 |
| 7.88.0 | 1 | 5.9 | 1.9% | 0 | 0 |
| 7.83.0 | 1 | 8.1 | 3.7% | 0 | 0 |
| 7.8.1 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.8 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.7.3 | 5 | 6.1 | 8.5% | 0 | 0 |
| 7.7.2 | 5 | 6.1 | 8.5% | 0 | 0 |