{"schema_version":1,"title":"Haxx vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 28 vulnerabilities in Haxx: 0 in the last 7 days and 9 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82209, was published on 6 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/haxx","json_url":"https://junglewise.ai/threats/vendors/haxx.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/haxx","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":10,"all_time":28,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":9,"last_90_days":9,"last_365_days":24},"latest":[{"cve":"CVE-2026-82209","cvss":8.2,"epss":0.0052,"slug":"cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie","title":"curl Public Suffix List domain boundary check bypass in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie"},{"cve":"CVE-2026-82208","cvss":7.5,"epss":0.0041,"slug":"cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend","title":"curl libcurl certificate validation bypass in wolfSSL backend","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.733+00:00","url":"https://junglewise.ai/threats/cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend"},{"cve":"CVE-2026-80255","cvss":7.5,"epss":0.0066,"slug":"cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab","title":"curl secure cookie attribute bypass with tab","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.623+00:00","url":"https://junglewise.ai/threats/cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab"},{"cve":"CVE-2026-80231","cvss":7.5,"epss":0.009,"slug":"cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings","title":"curl HTTPS connection reuse with mismatched CA store settings","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.5+00:00","url":"https://junglewise.ai/threats/cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings"},{"cve":"CVE-2026-80230","cvss":7.5,"epss":0.0055,"slug":"cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification","title":"curl public key pinning bypass with disabled peer verification","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.327+00:00","url":"https://junglewise.ai/threats/cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification"},{"cve":"CVE-2026-80229","cvss":7.5,"epss":0.0087,"slug":"cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections","title":"curl OpenSSL provider use-after-free in TLS connections","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.217+00:00","url":"https://junglewise.ai/threats/cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections"},{"cve":"CVE-2026-19931","cvss":9.8,"epss":0.0075,"slug":"cve-2026-19931-curl-negotiate-authentication-connection-reuse","title":"curl Negotiate authentication connection reuse","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.733+00:00","url":"https://junglewise.ai/threats/cve-2026-19931-curl-negotiate-authentication-connection-reuse"},{"cve":"CVE-2026-18924","cvss":9.1,"epss":0.0058,"slug":"cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free","title":"curl libcurl HTTP/2 server push use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.553+00:00","url":"https://junglewise.ai/threats/cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free"},{"cve":"CVE-2026-13608","cvss":7.4,"epss":0.0048,"slug":"cve-2026-13608-libcurl-sasl-negotiation-authentication-bypass-in-ldap","title":"libcurl SASL negotiation authentication bypass in LDAP","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:19.81+00:00","url":"https://junglewise.ai/threats/cve-2026-13608-libcurl-sasl-negotiation-authentication-bypass-in-ldap"},{"cve":"CVE-2026-7168","cvss":5.3,"epss":0.0059,"slug":"cve-2026-7168-curl-libcurl-digest-auth-state-leak-when-changing-proxies","title":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:57.2+00:00","url":"https://junglewise.ai/threats/cve-2026-7168-curl-libcurl-digest-auth-state-leak-when-changing-proxies"},{"cve":"CVE-2026-6429","cvss":5.3,"epss":0.0051,"slug":"cve-2026-6429-curl-libcurl-netrc-credential-leak-in-redirected-proxy-connections","title":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:56.93+00:00","url":"https://junglewise.ai/threats/cve-2026-6429-curl-libcurl-netrc-credential-leak-in-redirected-proxy-connections"},{"cve":"CVE-2026-6276","cvss":7.5,"epss":0.0035,"slug":"cve-2026-6276-curl-libcurl-cookie-leak-via-stale-custom-host-header","title":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy","severity":"high","exploited":false,"published_at":"2026-05-13T13:01:56.8+00:00","url":"https://junglewise.ai/threats/cve-2026-6276-curl-libcurl-cookie-leak-via-stale-custom-host-header"},{"cve":"CVE-2026-6253","cvss":5.9,"epss":0.0075,"slug":"cve-2026-6253-curl-proxy-credentials-leak-during-redirect-to-different-proxy","title":"curl might erroneously pass on credentials for a first proxy to a second\nproxy. This can happen when the following conditions are true: 1.","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:56.57+00:00","url":"https://junglewise.ai/threats/cve-2026-6253-curl-proxy-credentials-leak-during-redirect-to-different-proxy"},{"cve":"CVE-2026-5773","cvss":7.5,"epss":0.0066,"slug":"cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers","title":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers. libcurl features a pool of recent connections so that","severity":"high","exploited":false,"published_at":"2026-05-13T13:01:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers"},{"cve":"CVE-2026-5545","cvss":6.5,"epss":0.0051,"slug":"cve-2026-5545-curl-incorrect-connection-reuse-in-negotiate-authentication","title":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authentic","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:56.19+00:00","url":"https://junglewise.ai/threats/cve-2026-5545-curl-incorrect-connection-reuse-in-negotiate-authentication"},{"cve":"CVE-2026-4873","cvss":5.9,"epss":0.0036,"slug":"cve-2026-4873-curl-connection-reuse-ignores-tls-requirement-in-email-protocols","title":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool.","severity":"medium","exploited":false,"published_at":"2026-05-13T13:01:55.893+00:00","url":"https://junglewise.ai/threats/cve-2026-4873-curl-connection-reuse-ignores-tls-requirement-in-email-protocols"},{"cve":"CVE-2026-3784","cvss":6.5,"epss":0.0002,"slug":"cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials","title":"curl wrong proxy connection reuse with credentials","severity":"medium","exploited":false,"published_at":"2026-03-11T11:16:00.437+00:00","url":"https://junglewise.ai/threats/cve-2026-3784-curl-wrong-proxy-connection-reuse-with-credentials"},{"cve":"CVE-2025-15224","cvss":3.1,"epss":0.0049,"slug":"cve-2025-15224-curl-libssh-key-passphrase-bypass-without-agent-set","title":"curl libssh key passphrase bypass without agent set","severity":"low","exploited":false,"published_at":"2026-01-08T10:15:47.207+00:00","url":"https://junglewise.ai/threats/cve-2025-15224-curl-libssh-key-passphrase-bypass-without-agent-set"},{"cve":"CVE-2025-15079","cvss":5.3,"epss":0.0054,"slug":"cve-2025-15079-curl-libssh-global-known-hosts-override-in-sftp-scp","title":"curl libssh global known_hosts override in SFTP/SCP","severity":"medium","exploited":false,"published_at":"2026-01-08T10:15:47.1+00:00","url":"https://junglewise.ai/threats/cve-2025-15079-curl-libssh-global-known-hosts-override-in-sftp-scp"},{"cve":"CVE-2025-14819","cvss":5.3,"epss":0.0074,"slug":"cve-2025-14819-curl-libcurl-certificate-validation-bypass-in-openssl-backend","title":"curl libcurl certificate validation bypass in OpenSSL backend","severity":"medium","exploited":false,"published_at":"2026-01-08T10:15:46.73+00:00","url":"https://junglewise.ai/threats/cve-2025-14819-curl-libcurl-certificate-validation-bypass-in-openssl-backend"},{"cve":"CVE-2025-14524","cvss":5.3,"epss":0.0067,"slug":"cve-2025-14524-curl-bearer-token-leak-on-cross-protocol-redirect","title":"curl bearer token leak on cross-protocol redirect","severity":"medium","exploited":false,"published_at":"2026-01-08T10:15:46.607+00:00","url":"https://junglewise.ai/threats/cve-2025-14524-curl-bearer-token-leak-on-cross-protocol-redirect"},{"cve":"CVE-2025-14017","cvss":6.3,"epss":0.0012,"slug":"cve-2025-14017-curl-ldaps-thread-unsafe-tls-option-handling","title":"curl LDAPS thread-unsafe TLS option handling","severity":"medium","exploited":false,"published_at":"2026-01-08T10:15:45.667+00:00","url":"https://junglewise.ai/threats/cve-2025-14017-curl-ldaps-thread-unsafe-tls-option-handling"},{"cve":"CVE-2025-13034","cvss":5.9,"epss":0.0024,"slug":"cve-2025-13034-curl-certificate-pinning-bypass-in-quic-with-gnutls","title":"curl certificate pinning bypass in QUIC with GnuTLS","severity":"medium","exploited":false,"published_at":"2026-01-08T10:15:45.407+00:00","url":"https://junglewise.ai/threats/cve-2025-13034-curl-certificate-pinning-bypass-in-quic-with-gnutls"},{"cve":"CVE-2025-10966","cvss":4.3,"epss":0.0003,"slug":"cve-2025-10966-curl-missing-sftp-host-verification-in-wolfssh-backend","title":"curl missing SFTP host verification in wolfSSH backend","severity":"medium","exploited":false,"published_at":"2025-11-07T08:15:39.617+00:00","url":"https://junglewise.ai/threats/cve-2025-10966-curl-missing-sftp-host-verification-in-wolfssh-backend"},{"cve":"CVE-2025-9086","cvss":7.5,"epss":0.001,"slug":"cve-2025-9086-curl-out-of-bounds-read-in-cookie-path-comparison","title":"curl out-of-bounds read in cookie path comparison","severity":"high","exploited":false,"published_at":"2025-09-12T06:15:44.1+00:00","url":"https://junglewise.ai/threats/cve-2025-9086-curl-out-of-bounds-read-in-cookie-path-comparison"}],"vendor":{"hub":true,"name":"Haxx","slug":"haxx","homepage":"https://haxx.se/","description":"Haxx is a Swedish organization and web domain associated with the development of the curl data transfer tool.","url":"https://junglewise.ai/threats/vendors/haxx"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-19931","cvss":9.8,"epss":0.0075,"slug":"cve-2026-19931-curl-negotiate-authentication-connection-reuse","title":"curl Negotiate authentication connection reuse","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.733+00:00","url":"https://junglewise.ai/threats/cve-2026-19931-curl-negotiate-authentication-connection-reuse"},{"cve":"CVE-2026-18924","cvss":9.1,"epss":0.0058,"slug":"cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free","title":"curl libcurl HTTP/2 server push use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.553+00:00","url":"https://junglewise.ai/threats/cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free"},{"cve":"CVE-2026-82209","cvss":8.2,"epss":0.0052,"slug":"cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie","title":"curl Public Suffix List domain boundary check bypass in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie"},{"cve":"CVE-2026-80231","cvss":7.5,"epss":0.009,"slug":"cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings","title":"curl HTTPS connection reuse with mismatched CA store settings","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.5+00:00","url":"https://junglewise.ai/threats/cve-2026-80231-curl-https-connection-reuse-with-mismatched-ca-store-settings"},{"cve":"CVE-2026-80229","cvss":7.5,"epss":0.0087,"slug":"cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections","title":"curl OpenSSL provider use-after-free in TLS connections","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.217+00:00","url":"https://junglewise.ai/threats/cve-2026-80229-curl-openssl-provider-use-after-free-in-tls-connections"},{"cve":"CVE-2026-80255","cvss":7.5,"epss":0.0066,"slug":"cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab","title":"curl secure cookie attribute bypass with tab","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.623+00:00","url":"https://junglewise.ai/threats/cve-2026-80255-curl-secure-cookie-attribute-bypass-with-tab"},{"cve":"CVE-2026-5773","cvss":7.5,"epss":0.0066,"slug":"cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers","title":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers. libcurl features a pool of recent connections so that","severity":"high","exploited":false,"published_at":"2026-05-13T13:01:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-5773-curl-libcurl-incorrect-connection-reuse-in-smb-transfers"},{"cve":"CVE-2026-80230","cvss":7.5,"epss":0.0055,"slug":"cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification","title":"curl public key pinning bypass with disabled peer verification","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.327+00:00","url":"https://junglewise.ai/threats/cve-2026-80230-curl-public-key-pinning-bypass-with-disabled-peer-verification"},{"cve":"CVE-2026-82208","cvss":7.5,"epss":0.0041,"slug":"cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend","title":"curl libcurl certificate validation bypass in wolfSSL backend","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.733+00:00","url":"https://junglewise.ai/threats/cve-2026-82208-curl-libcurl-certificate-validation-bypass-in-wolfssl-backend"},{"cve":"CVE-2026-6276","cvss":7.5,"epss":0.0035,"slug":"cve-2026-6276-curl-libcurl-cookie-leak-via-stale-custom-host-header","title":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy","severity":"high","exploited":false,"published_at":"2026-05-13T13:01:56.8+00:00","url":"https://junglewise.ai/threats/cve-2026-6276-curl-libcurl-cookie-leak-via-stale-custom-host-header"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"Haxx Curl","slug":"curl","vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/curl"},{"name":"Haxx Libcurl","slug":"libcurl","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/libcurl"}]}