CVE-2022-30115Medium· 4.3▾ SunlitUsing its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and not using thetrailing dot in the URL.
curl >= 7.82.0, < 7.83.1hci_bootstrap_osclustered_data_ontapsolidfire,_enterprise_sds_&_hci_storage_nodesolidfire_&_hci_management_nodeh300s_firmwareh500s_firmwareh700s_firmwareh410s_firmwareuniversal_forwarder >= 8.2.0, < 8.2.12universal_forwarder >= 9.0.0, < 9.0.6universal_forwarder = 9.1.0Upgrade past the affected range:
curl 7.83.1universal_forwarder 9.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2022-27778High· 8.1A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
CVE-2026-6276High· 7.5Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…
CVE-2026-4873Medium· 5.9A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool
CVE-2021-22901High· 8.1curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection
CVE-2026-6429Medium· 5.3When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CVE-2026-7168Medium· 5.3Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…