---
id: CVE-2022-27778
title: >-
  A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove
  the wrong file when `--no-clobber` is used together with `--remove-on-error`.
summary: >-
  A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove
  the wrong file when `--no-clobber` is used together with `--remove-on-error`.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'
cwe:
  - CWE-706
  - CWE-706
vendor: haxx
product: curl
affected:
  - curl = 7.83.0
  - active_iq_unified_manager
  - clustered_data_ontap
  - oncommand_insight
  - oncommand_workflow_automation
  - snapcenter
  - solidfire_&_hci_management_node
  - h300s_firmware
  - bh500s_firmware
  - h700s_firmware
  - h410s_firmware
  - hci_compute_node_firmware
  - mysql_server <= 5.7.38
  - 'mysql_server >= 8.0.0, <= 8.0.29'
  - 'universal_forwarder >= 8.2.0, < 8.2.12'
  - 'universal_forwarder >= 9.0.0, < 9.0.6'
  - universal_forwarder = 9.1.0
patched:
  - universal_forwarder 9.0.6
published: '2022-06-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:45.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-27778'
references:
  - url: 'https://hackerone.com/reports/1553598'
    label: support@hackerone.com
  - url: 'https://security.netapp.com/advisory/ntap-20220609-0009/'
    label: support@hackerone.com
  - url: 'https://security.netapp.com/advisory/ntap-20220729-0004/'
    label: support@hackerone.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: support@hackerone.com
  - url: 'https://hackerone.com/reports/1553598'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220609-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220729-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03808
epssPercentile: 0.89752
ingestedAt: '2026-10-08T22:11:53.750Z'
---

## Overview

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

## Affected

- `curl = 7.83.0`
- `active_iq_unified_manager`
- `clustered_data_ontap`
- `oncommand_insight`
- `oncommand_workflow_automation`
- `snapcenter`
- `solidfire_&_hci_management_node`
- `h300s_firmware`
- `bh500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `hci_compute_node_firmware`
- `mysql_server <= 5.7.38`
- `mysql_server >= 8.0.0, <= 8.0.29`
- `universal_forwarder >= 8.2.0, < 8.2.12`
- `universal_forwarder >= 9.0.0, < 9.0.6`
- `universal_forwarder = 9.1.0`

## Remediation

Upgrade past the affected range:

- `universal_forwarder 9.0.6`
