Technology · Haxx
Haxx Libcurl vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in Haxx Libcurl: 0 in the last 7 days and 10 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82208, was published on 6 September 2026.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 2
- Exploited in the wild
- 0
About Haxx Libcurl
A free and easy-to-use client-side URL transfer library, supporting a wide range of protocols.
Latest Haxx Libcurl vulnerabilities
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-8932: curl libcurl authentication bypass via improper mTLS connection reuseinfo
- CVE-2026-8927: curl libcurl authentication state leak in proxy handle reuseinfo
- CVE-2026-8926: curl password leak in .netrc credential lookupinfo
- CVE-2026-8924: curl cookie parsing bypass via trailing dot hostnameinfoCVSS 0
- CVE-2026-8458: curl libcurl incorrect connection reuse for Negotiate servicesinfoCVSS 0
- CVE-2026-8286: curl wrong STARTTLS connection reuseinfo
- CVE-2026-11352: curl QUIC infinite loop in UDP receive functioninfoCVSS 0
- CVE-2026-10536: curl libcurl use-after-free in HTTP/2 stream-dependency treeinfoCVSS 3.3
- CVE-2026-7168: Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-7009: curl OCSP stapling bypass when using Apple SecTrustmediumCVSS 5.3
- CVE-2026-6429: When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-6276: Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done…highCVSS 7.5EPSS 0.4%
- CVE-2026-6253: curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following…mediumCVSS 5.9EPSS 0.8%
- CVE-2026-5545: libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-4873: A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same…mediumCVSS 5.9EPSS 0.4%
- CVE-2025-14819: curl libcurl certificate validation bypass in OpenSSL backendmediumCVSS 5.3EPSS 0.7%
- CVE-2025-9086: curl out-of-bounds read in cookie path comparisonhighCVSS 7.5EPSS 0.1%
- CVE-2023-38546: curl libcurl cookie injection via curl_easy_duphandlelowCVSS 3.7
- CVE-2023-38545: curl SOCKS5 heap buffer overflow during handshakecriticalCVSS 9.8
Most severe Haxx Libcurl vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-38545: curl SOCKS5 heap buffer overflow during handshakecriticalCVSS 9.8
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
- CVE-2026-6276: Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done…highCVSS 7.5EPSS 0.4%
- CVE-2025-9086: curl out-of-bounds read in cookie path comparisonhighCVSS 7.5EPSS 0.1%
- CVE-2026-5545: libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-6253: curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following…mediumCVSS 5.9EPSS 0.8%
- CVE-2026-4873: A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same…mediumCVSS 5.9EPSS 0.4%
- CVE-2025-14819: curl libcurl certificate validation bypass in OpenSSL backendmediumCVSS 5.3EPSS 0.7%
- CVE-2026-7168: Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then…mediumCVSS 5.3EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 8 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 1 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/libcurl.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Haxx Libcurl vulnerabilities", https://junglewise.ai/threats/technologies/libcurl, 26 September 2026.