{"schema_version":1,"title":"Haxx Curl vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in Haxx Curl: 0 in the last 7 days and 23 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82209, was published on 6 September 2026.","url":"https://junglewise.ai/threats/technologies/curl","json_url":"https://junglewise.ai/threats/technologies/curl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/curl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":43,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":9,"last_90_days":23,"last_365_days":39},"latest":[{"cve":"CVE-2026-82209","cvss":8.2,"epss":0.0052,"slug":"cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie","title":"curl Public Suffix List domain boundary check bypass in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie"},{"cve":"CVE-2026-82208","cvss":7.5,"epss":0.0041,"slug":"cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend","title":"curl libcurl certificate validation bypass in wolfSSL backend","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.733+00:00","url":"https://junglewise.ai/threats/cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend"},{"cve":"CVE-2026-80255","cvss":7.5,"epss":0.0066,"slug":"cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab","title":"curl secure cookie attribute bypass with tab","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.623+00:00","url":"https://junglewise.ai/threats/cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab"},{"cve":"CVE-2026-80231","cvss":7.5,"epss":0.009,"slug":"cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings","title":"curl HTTPS connection reuse with mismatched CA store settings","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.5+00:00","url":"https://junglewise.ai/threats/cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings"},{"cve":"CVE-2026-80230","cvss":7.5,"epss":0.0055,"slug":"cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification","title":"curl public key pinning bypass with disabled peer verification","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.327+00:00","url":"https://junglewise.ai/threats/cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification"},{"cve":"CVE-2026-80229","cvss":7.5,"epss":0.0087,"slug":"cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections","title":"curl OpenSSL provider use-after-free in TLS connections","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.217+00:00","url":"https://junglewise.ai/threats/cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections"},{"cve":"CVE-2026-19931","cvss":9.8,"epss":0.0075,"slug":"cve-2026-19931-curl-negotiate-authentication-connection-reuse","title":"curl Negotiate authentication connection reuse","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.733+00:00","url":"https://junglewise.ai/threats/cve-2026-19931-curl-negotiate-authentication-connection-reuse"},{"cve":"CVE-2026-18924","cvss":9.1,"epss":0.0058,"slug":"cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free","title":"curl libcurl HTTP/2 server push use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.553+00:00","url":"https://junglewise.ai/threats/cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free"},{"cve":"CVE-2026-13608","cvss":7.4,"epss":0.0048,"slug":"cve-2026-13608-libcurl-sasl-negotiation-authentication-bypass-in-ldap","title":"libcurl SASL negotiation authentication bypass in LDAP","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:19.81+00:00","url":"https://junglewise.ai/threats/cve-2026-13608-libcurl-sasl-negotiation-authentication-bypass-in-ldap"},{"cve":"CVE-2026-9547","cvss":0,"slug":"cve-2026-9547-curl-libcurl-improper-host-validation-in-ssh-key-callback","title":"curl libcurl improper host validation in SSH key callback","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.99+00:00","url":"https://junglewise.ai/threats/cve-2026-9547-curl-libcurl-improper-host-validation-in-ssh-key-callback"},{"cve":"CVE-2026-9546","slug":"cve-2026-9546-curl-libcurl-information-exposure-via-persistent-referer-header","title":"curl libcurl information exposure via persistent Referer header","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.893+00:00","url":"https://junglewise.ai/threats/cve-2026-9546-curl-libcurl-information-exposure-via-persistent-referer-header"},{"cve":"CVE-2026-9545","slug":"cve-2026-9545-curl-information-exposure-via-http-3-early-data-transmission","title":"curl information exposure via HTTP/3 early data transmission","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.807+00:00","url":"https://junglewise.ai/threats/cve-2026-9545-curl-information-exposure-via-http-3-early-data-transmission"},{"cve":"CVE-2026-9080","cvss":0,"slug":"cve-2026-9080-curl-libcurl-use-after-free-in-curlmopt-socketfunction-callback","title":"curl libcurl use-after-free in CURLMOPT_SOCKETFUNCTION callback","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.713+00:00","url":"https://junglewise.ai/threats/cve-2026-9080-curl-libcurl-use-after-free-in-curlmopt-socketfunction-callback"},{"cve":"CVE-2026-9079","cvss":0,"slug":"cve-2026-9079-curl-libcurl-stale-proxy-password-leak","title":"curl libcurl stale proxy password leak","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.62+00:00","url":"https://junglewise.ai/threats/cve-2026-9079-curl-libcurl-stale-proxy-password-leak"},{"cve":"CVE-2026-8926","slug":"cve-2026-8926-curl-password-leak-in-netrc-credential-lookup","title":"curl password leak in .netrc credential lookup","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:25.037+00:00","url":"https://junglewise.ai/threats/cve-2026-8926-curl-password-leak-in-netrc-credential-lookup"},{"cve":"CVE-2026-8925","cvss":0,"slug":"cve-2026-8925-curl-sasl-double-free-in-gsasl-context-cleanup","title":"curl SASL double-free in GSASL context cleanup","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:24.95+00:00","url":"https://junglewise.ai/threats/cve-2026-8925-curl-sasl-double-free-in-gsasl-context-cleanup"},{"cve":"CVE-2026-8924","cvss":0,"slug":"cve-2026-8924-curl-cookie-parsing-bypass-via-trailing-dot-hostname","title":"curl cookie parsing bypass via trailing dot hostname","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-8924-curl-cookie-parsing-bypass-via-trailing-dot-hostname"},{"cve":"CVE-2026-8286","slug":"cve-2026-8286-curl-wrong-starttls-connection-reuse","title":"curl wrong STARTTLS connection reuse","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:24.453+00:00","url":"https://junglewise.ai/threats/cve-2026-8286-curl-wrong-starttls-connection-reuse"},{"cve":"CVE-2026-12064","cvss":0,"slug":"cve-2026-12064-curl-ssh-host-verification-bypass-via-schemeless-urls-and-proto","title":"curl SSH host verification bypass via schemeless URLs and proto-default","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:24.217+00:00","url":"https://junglewise.ai/threats/cve-2026-12064-curl-ssh-host-verification-bypass-via-schemeless-urls-and-proto"},{"cve":"CVE-2026-11856","slug":"cve-2026-11856-curl-libcurl-cross-origin-digest-authentication-state-leak","title":"curl libcurl cross-origin Digest authentication state leak","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:23.973+00:00","url":"https://junglewise.ai/threats/cve-2026-11856-curl-libcurl-cross-origin-digest-authentication-state-leak"},{"cve":"CVE-2026-11586","slug":"cve-2026-11586-curl-memory-exhaustion-in-websocket-ping-handling","title":"curl memory exhaustion in WebSocket PING handling","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:23.883+00:00","url":"https://junglewise.ai/threats/cve-2026-11586-curl-memory-exhaustion-in-websocket-ping-handling"},{"cve":"CVE-2026-11564","slug":"cve-2026-11564-curl-libcurl-improper-certificate-validation-via-native-ca-trust","title":"curl libcurl improper certificate validation via native CA trust persistence","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:23.79+00:00","url":"https://junglewise.ai/threats/cve-2026-11564-curl-libcurl-improper-certificate-validation-via-native-ca-trust"},{"cve":"CVE-2026-11352","cvss":0,"slug":"cve-2026-11352-curl-quic-infinite-loop-in-udp-receive-function","title":"curl QUIC infinite loop in UDP receive function","severity":"info","exploited":false,"published_at":"2026-07-03T07:16:23.693+00:00","url":"https://junglewise.ai/threats/cve-2026-11352-curl-quic-infinite-loop-in-udp-receive-function"},{"cve":"CVE-2026-7168","cvss":5.3,"epss":0.0059,"slug":"cve-2026-7168-curl-libcurl-digest-auth-state-leak-when-changing-proxies","title":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:57.2+00:00","url":"https://junglewise.ai/threats/cve-2026-7168-curl-libcurl-digest-auth-state-leak-when-changing-proxies"},{"cve":"CVE-2026-7009","cvss":5.3,"slug":"cve-2026-7009-curl-ocsp-stapling-bypass-when-using-apple-sectrust","title":"curl OCSP stapling bypass when using Apple SecTrust","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:57.1+00:00","url":"https://junglewise.ai/threats/cve-2026-7009-curl-ocsp-stapling-bypass-when-using-apple-sectrust"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":14},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Haxx Libcurl","slug":"libcurl","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/libcurl"}],"technology":{"hub":true,"name":"Haxx Curl","slug":"curl","vendor":{"name":"Haxx","slug":"haxx","url":"https://junglewise.ai/threats/vendors/haxx"},"aliases":[],"category":"library","homepage":"https://curl.se/","repo_url":"https://github.com/curl/curl","description":"A command-line tool and library for transferring data with URLs.","url":"https://junglewise.ai/threats/technologies/curl"},"most_severe":[{"cve":"CVE-2026-19931","cvss":9.8,"epss":0.0075,"slug":"cve-2026-19931-curl-negotiate-authentication-connection-reuse","title":"curl Negotiate authentication connection reuse","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.733+00:00","url":"https://junglewise.ai/threats/cve-2026-19931-curl-negotiate-authentication-connection-reuse"},{"cve":"CVE-2023-38545","cvss":9.8,"slug":"cve-2023-38545-curl-socks5-heap-buffer-overflow-during-handshake","title":"curl SOCKS5 heap buffer overflow during handshake","severity":"critical","exploited":false,"published_at":"2023-10-18T04:15:11.077+00:00","url":"https://junglewise.ai/threats/cve-2023-38545-curl-socks5-heap-buffer-overflow-during-handshake"},{"cve":"CVE-2026-18924","cvss":9.1,"epss":0.0058,"slug":"cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free","title":"curl libcurl HTTP/2 server push use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.553+00:00","url":"https://junglewise.ai/threats/cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free"},{"cve":"CVE-2026-82209","cvss":8.2,"epss":0.0052,"slug":"cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie","title":"curl Public Suffix List domain boundary check bypass in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie"},{"cve":"CVE-2026-80231","cvss":7.5,"epss":0.009,"slug":"cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings","title":"curl HTTPS connection reuse with mismatched CA store settings","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.5+00:00","url":"https://junglewise.ai/threats/cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings"},{"cve":"CVE-2026-80229","cvss":7.5,"epss":0.0087,"slug":"cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections","title":"curl OpenSSL provider use-after-free in TLS connections","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.217+00:00","url":"https://junglewise.ai/threats/cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections"},{"cve":"CVE-2026-80255","cvss":7.5,"epss":0.0066,"slug":"cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab","title":"curl secure cookie attribute bypass with tab","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.623+00:00","url":"https://junglewise.ai/threats/cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab"},{"cve":"CVE-2026-5773","cvss":7.5,"epss":0.0066,"slug":"cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers","title":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers. libcurl features a pool of recent connections so that","severity":"high","exploited":false,"published_at":"2026-05-13T13:01:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers"},{"cve":"CVE-2026-80230","cvss":7.5,"epss":0.0055,"slug":"cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification","title":"curl public key pinning bypass with disabled peer verification","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.327+00:00","url":"https://junglewise.ai/threats/cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification"},{"cve":"CVE-2026-82208","cvss":7.5,"epss":0.0041,"slug":"cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend","title":"curl libcurl certificate validation bypass in wolfSSL backend","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.733+00:00","url":"https://junglewise.ai/threats/cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}