Technology · Haxx
Haxx Curl vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 43 vulnerabilities in Haxx Curl: 0 in the last 7 days and 23 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82209, was published on 6 September 2026.
- Last 7 days
- 0
- Last 90 days
- 23
- Critical, all time
- 3
- Exploited in the wild
- 0
About Haxx Curl
A command-line tool and library for transferring data with URLs.
Latest Haxx Curl vulnerabilities
- CVE-2026-82209: curl Public Suffix List domain boundary check bypass in cookie handlinghighCVSS 8.2EPSS 0.5%
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
- CVE-2026-80255: curl secure cookie attribute bypass with tabhighCVSS 7.5EPSS 0.7%
- CVE-2026-80231: curl HTTPS connection reuse with mismatched CA store settingshighCVSS 7.5EPSS 0.9%
- CVE-2026-80230: curl public key pinning bypass with disabled peer verificationhighCVSS 7.5EPSS 0.5%
- CVE-2026-80229: curl OpenSSL provider use-after-free in TLS connectionshighCVSS 7.5EPSS 0.9%
- CVE-2026-19931: curl Negotiate authentication connection reusecriticalCVSS 9.8EPSS 0.8%
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-13608: libcurl SASL negotiation authentication bypass in LDAPhighCVSS 7.4EPSS 0.5%
- CVE-2026-9547: curl libcurl improper host validation in SSH key callbackinfoCVSS 0
- CVE-2026-9546: curl libcurl information exposure via persistent Referer headerinfo
- CVE-2026-9545: curl information exposure via HTTP/3 early data transmissioninfo
- CVE-2026-9080: curl libcurl use-after-free in CURLMOPT_SOCKETFUNCTION callbackinfoCVSS 0
- CVE-2026-9079: curl libcurl stale proxy password leakinfoCVSS 0
- CVE-2026-8926: curl password leak in .netrc credential lookupinfo
- CVE-2026-8925: curl SASL double-free in GSASL context cleanupinfoCVSS 0
- CVE-2026-8924: curl cookie parsing bypass via trailing dot hostnameinfoCVSS 0
- CVE-2026-8286: curl wrong STARTTLS connection reuseinfo
- CVE-2026-12064: curl SSH host verification bypass via schemeless URLs and proto-defaultinfoCVSS 0
- CVE-2026-11856: curl libcurl cross-origin Digest authentication state leakinfo
- CVE-2026-11586: curl memory exhaustion in WebSocket PING handlinginfo
- CVE-2026-11564: curl libcurl improper certificate validation via native CA trust persistenceinfo
- CVE-2026-11352: curl QUIC infinite loop in UDP receive functioninfoCVSS 0
- CVE-2026-7168: Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-7009: curl OCSP stapling bypass when using Apple SecTrustmediumCVSS 5.3
Most severe Haxx Curl vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-19931: curl Negotiate authentication connection reusecriticalCVSS 9.8EPSS 0.8%
- CVE-2023-38545: curl SOCKS5 heap buffer overflow during handshakecriticalCVSS 9.8
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-82209: curl Public Suffix List domain boundary check bypass in cookie handlinghighCVSS 8.2EPSS 0.5%
- CVE-2026-80231: curl HTTPS connection reuse with mismatched CA store settingshighCVSS 7.5EPSS 0.9%
- CVE-2026-80229: curl OpenSSL provider use-after-free in TLS connectionshighCVSS 7.5EPSS 0.9%
- CVE-2026-80255: curl secure cookie attribute bypass with tabhighCVSS 7.5EPSS 0.7%
- CVE-2026-5773: libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent…highCVSS 7.5EPSS 0.7%
- CVE-2026-80230: curl public key pinning bypass with disabled peer verificationhighCVSS 7.5EPSS 0.5%
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 14 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 9 | 2 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/curl.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Haxx Curl vulnerabilities", https://junglewise.ai/threats/technologies/curl, 26 September 2026.