Curl
This hub aggregates every CVE we track for Curl, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
196
CVEs tracked
32
Critical
56
High
0
In CISA KEV
Severity distribution
MEDIUM90HIGH56CRITICAL32LOW18
Monthly trend
1
0
1
1
0
3
0
0
2
1
0
0
2
0
1
0
6
1
4
0
8
0
18
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Curl.
- CVE-2026-9547SSH improper host validation7.4
- CVE-2026-9546sending old referer7.5
- CVE-2026-9545exposing HTTP/3 early data7.5
- CVE-2026-9080UAF after pause in socket callback7.3
- CVE-2026-9079stale proxy password leak9.8
- CVE-2026-8932incomplete mTLS config matching in conn reuse7.5
- CVE-2026-8927env-set cross-proxy Digest auth state leak9.1
- CVE-2026-8926password leak with netrc and user in URL9.1
- CVE-2026-8925SASL double-free9.8
- CVE-2026-8924trailing dot domain super cookie9.1
- CVE-2026-8458wrong reuse for different services6.5
- CVE-2026-8286wrong STARTTLS connection reuse8.1
- CVE-2026-12064proto-default skips SSH verification7.5
- CVE-2026-11856cross-origin Digest auth state leak9.8
- CVE-2026-11586WS Auto-PONG memory exhaustion7.5
Product normalization is registry-driven with AI assist and human review. How it works