Vendor
Haxx vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Haxx: 0 in the last 7 days and 9 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82209, was published on 6 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 2
- Exploited in the wild
- 0
About Haxx
Haxx is a Swedish organization and web domain associated with the development of the curl data transfer tool.
Haxx technologies
Latest Haxx vulnerabilities
- CVE-2026-82209: curl Public Suffix List domain boundary check bypass in cookie handlinghighCVSS 8.2EPSS 0.5%
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
- CVE-2026-80255: curl secure cookie attribute bypass with tabhighCVSS 7.5EPSS 0.7%
- CVE-2026-80231: curl HTTPS connection reuse with mismatched CA store settingshighCVSS 7.5EPSS 0.9%
- CVE-2026-80230: curl public key pinning bypass with disabled peer verificationhighCVSS 7.5EPSS 0.5%
- CVE-2026-80229: curl OpenSSL provider use-after-free in TLS connectionshighCVSS 7.5EPSS 0.9%
- CVE-2026-19931: curl Negotiate authentication connection reusecriticalCVSS 9.8EPSS 0.8%
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-13608: libcurl SASL negotiation authentication bypass in LDAPhighCVSS 7.4EPSS 0.5%
- CVE-2026-7168: Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-6429: When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-6276: Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done…highCVSS 7.5EPSS 0.4%
- CVE-2026-6253: curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following…mediumCVSS 5.9EPSS 0.8%
- CVE-2026-5773: libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent…highCVSS 7.5EPSS 0.7%
- CVE-2026-5545: libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-4873: A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same…mediumCVSS 5.9EPSS 0.4%
- CVE-2026-3784: curl wrong proxy connection reuse with credentialsmediumCVSS 6.5EPSS 0.0%
- CVE-2025-15224: curl libssh key passphrase bypass without agent setlowCVSS 3.1EPSS 0.5%
- CVE-2025-15079: curl libssh global known_hosts override in SFTP/SCPmediumCVSS 5.3EPSS 0.5%
- CVE-2025-14819: curl libcurl certificate validation bypass in OpenSSL backendmediumCVSS 5.3EPSS 0.7%
- CVE-2025-14524: curl bearer token leak on cross-protocol redirectmediumCVSS 5.3EPSS 0.7%
- CVE-2025-14017: curl LDAPS thread-unsafe TLS option handlingmediumCVSS 6.3EPSS 0.1%
- CVE-2025-13034: curl certificate pinning bypass in QUIC with GnuTLSmediumCVSS 5.9EPSS 0.2%
- CVE-2025-10966: curl missing SFTP host verification in wolfSSH backendmediumCVSS 4.3EPSS 0.0%
- CVE-2025-9086: curl out-of-bounds read in cookie path comparisonhighCVSS 7.5EPSS 0.1%
Most severe Haxx vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-19931: curl Negotiate authentication connection reusecriticalCVSS 9.8EPSS 0.8%
- CVE-2026-18924: curl libcurl HTTP/2 server push use-after-freecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-82209: curl Public Suffix List domain boundary check bypass in cookie handlinghighCVSS 8.2EPSS 0.5%
- CVE-2026-80231: curl HTTPS connection reuse with mismatched CA store settingshighCVSS 7.5EPSS 0.9%
- CVE-2026-80229: curl OpenSSL provider use-after-free in TLS connectionshighCVSS 7.5EPSS 0.9%
- CVE-2026-80255: curl secure cookie attribute bypass with tabhighCVSS 7.5EPSS 0.7%
- CVE-2026-5773: libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent…highCVSS 7.5EPSS 0.7%
- CVE-2026-80230: curl public key pinning bypass with disabled peer verificationhighCVSS 7.5EPSS 0.5%
- CVE-2026-82208: curl libcurl certificate validation bypass in wolfSSL backendhighCVSS 7.5EPSS 0.4%
- CVE-2026-6276: Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done…highCVSS 7.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 9 | 2 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/haxx.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Haxx vulnerabilities", https://junglewise.ai/threats/vendors/haxx, 28 September 2026.