CVE-2022-27778High· 8.1▾ TwilightA use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.8%
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when --no-clobber is used together with --remove-on-error.
curl = 7.83.0active_iq_unified_managerclustered_data_ontaponcommand_insightoncommand_workflow_automationsnapcentersolidfire_&_hci_management_nodeh300s_firmwarebh500s_firmwareh700s_firmwareh410s_firmwarehci_compute_node_firmwaremysql_server <= 5.7.38mysql_server >= 8.0.0, <= 8.0.29universal_forwarder >= 8.2.0, < 8.2.12universal_forwarder >= 9.0.0, < 9.0.6universal_forwarder = 9.1.0Upgrade past the affected range:
universal_forwarder 9.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2022-30115Medium· 4.3Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL
CVE-2021-22901High· 8.1curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection
CVE-2026-6429Medium· 5.3When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CVE-2026-7168Medium· 5.3Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…
CVE-2026-6276High· 7.5Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…
CVE-2026-5773High· 7.5libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…