In lib/url.c, the detect_proxy function uses a fixed-size buffer, proxy_env[20], to construct proxy environment variable names (e.g., http_proxy). ...
Summary A recent migration of the Digest authentication parsing logic to the curlx_str (strparse) API introduced two functional parsing regressions...
During a review of curl's handling of response decompression, it was noticed that no limit exists on the final uncompressed data volume from compre...
================================================================================ DESCRIPTION: =====================================================...
## Vulnerability Details - **CVSSv3:** 7.5 (High) - Windows only - **File:** `lib/urlapi.c:974-1030` - **Issue:** Windows file:// URLs accept UNC p...
## Summary: A security feature bypass exists in `libcurl` when built with the **wolfSSL** backend and **HTTP/3** support. The Certificate Pinning f...
Summary: A heap-based buffer overflow exists in the AmigaOS-specific DNS resolution function Curl_ipv4_resolve_r located in lib/amigaos.c. The fu...
# cURL Alt-Svc Parser Stack Buffer Overflow Vulnerability Analysis ## In Simple Terms A critical security flaw was discovered in cURL (versions 7...
** Buffer Overflow in cURL AmigaOS Socket Implementation** ## **Report Metadata** - **Report ID:** H1-CURL-AMIGAOS-001 - **Report Title:** Heap Bu...
## Summary: The `dedotdotify()` function in `lib/urlapi.c` is responsible for removing path traversal sequences (`../` and `./`) from URLs accordi...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.