---
id: CVE-2023-27534
title: 'curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)'
summary: >-
  A path traversal vulnerability exists in curl <8.0.0 SFTP implementation
  causes the tilde (~) character to be wrongly replaced when used as a prefix in
  the first path element, in addition to its intended use as the first element
  to indicat…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat Enterprise Linux BaseOS (v. 9)
affected:
  - net_core_3_1_on_red_hat_enterprise_linux
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux 8
  - jboss_core_services_on_rhel_7_server
  - jboss_core_services_on_rhel 8
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_v_9
patched:
  - jboss_core_services_on_rhel_7_server
  - jboss_core_services_on_rhel 8
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_v_9
published: '2023-03-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T05:52:29+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27534.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27534.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-27534'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2179069'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-27534'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27534'
  - url: 'https://curl.se/docs/CVE-2023-27534.html'
  - url: 'https://access.redhat.com/errata/RHSA-2023:3354'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6679'
  - url: 'https://hackerone.com/reports/1892351'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/
    label: FEDORA-2023-7e7414e64d
  - url: 'https://security.netapp.com/advisory/ntap-20230420-0012/'
  - url: 'https://security.gentoo.org/glsa/202310-12'
    label: GLSA-202310-12
  - url: 'https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html'
    label: >-
      [debian-lts-announce] 20240317 [SECURITY] [DLA 3763-1] curl security
      update
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - exploit-available
  - score-dispute
epss: 0.02195
epssPercentile: 0.81739
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-04-23T13:29:22.277594Z'
scores:
  vendor: 3.7
  adp: 8.8
ingestedAt: '2026-09-18T15:44:31.588Z'
---

## Overview

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

## Vendor advisories

- **RHSA-2023:3354** · Red Hat · fixed in: Red Hat JBoss Core Services on RHEL 7 Server, Red Hat JBoss Core Services on RHEL 8 · released 2023-06-05 · [advisory](https://access.redhat.com/errata/RHSA-2023:3354)
- **RHSA-2023:6679** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6679)
- **Red Hat VEX** · Low · affected: .NET Core 3.1 on Red Hat Enterprise Linux, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: .NET Core 3.1 on Red Hat Enterprise Linux, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27534.json)

**curl: SFTP path ~ resolving discrepancy** — rated Low by Red Hat. Released 2023-03-20, updated 2026-09-21.

Affected:

- .NET Core 3.1 on Red Hat Enterprise Linux
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8

Fixed:

- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)

No fix planned:

- .NET Core 3.1 on Red Hat Enterprise Linux
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8

Not affected:

- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Applications using the APR libraries, such as httpd, must be restarted for this update to take effect. After installing the updated packages, the httpd daemon will be restarted automatically. https://access.redhat.com/errata/RHSA-2023:3354
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6679
