Libcurl
Vendor:
First CVE: May 2, 2005 · Active for 21 years
61
Total CVEs
More Total CVEs than 98% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libcurl over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 5, 2025
534 days ago
CVE Severity & Scoring
Libcurl61 CVEs
48%
30%
18%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.3%)
Network37 (60.7%)
Unknown22 (36.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (50.8%)
High8 (13.1%)
Unknown22 (36.1%)
User Interaction
None36 (59.0%)
Unknown22 (36.1%)
Required3 (4.9%)
Privileges Required
Low4 (6.6%)
High0 (0.0%)
None35 (57.4%)
Unknown22 (36.1%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38545CRITICAL This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is asked to pass along the host name to the SOCKS5 proxy to allow
that to resolve the ad | Oct 18, 2023 | 9.8 | 76 | NO | NO |
CVE-2019-5436HIGH A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | May 28, 2019 | 7.8 | 46 | NO | NO |
CVE-2013-0249HIGH Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authe | Mar 8, 2013 | 7.5 | 44 | NO | YES |
CVE-2019-3822CRITICAL libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_cre | Feb 6, 2019 | 9.8 | 38 | NO | NO |
CVE-2017-8817CRITICAL The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspeci | Nov 29, 2017 | 9.8 | 37 | NO | NO |
CVE-2017-8816CRITICAL The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, | Nov 29, 2017 | 9.8 | 36 | NO | NO |
CVE-2016-7167CRITICAL Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have un | Oct 7, 2016 | 9.8 | 36 | NO | NO |
CVE-2015-3145HIGH The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of | Apr 24, 2015 | 7.5 | 36 | NO | NO |
CVE-2016-5420HIGH curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the | Aug 10, 2016 | 7.5 | 35 | NO | NO |
CVE-2016-8622CRITICAL The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination | Jul 31, 2018 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.6% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For Libcurl
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.8.0 | 1 | 4.3 | 0.8% | 0 | 0 |
| 7.9.8 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.7 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.6 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.5 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.4 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.3 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.2 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9.1 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.9 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.88.1 | 1 | 5.9 | 1.9% | 0 | 0 |
| 7.88.0 | 1 | 5.9 | 1.9% | 0 | 0 |
| 7.8.1 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.8 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.7.3 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.7.2 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.7.1 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.7 | 3 | 6.2 | 8.8% | 0 | 0 |
| 7.6.1 | 1 | 4.3 | 6.8% | 0 | 0 |
| 7.6 | 1 | 4.3 | 6.8% | 0 | 0 |