## Summary: curl is vulnerable to silent Man-in-the-Middle (MITM) attacks due to its design, which implicitly trusts the CA certificate path specif...
SMTP CRLF Injection Vulnerability in curl/libcurl ## Vulnerability ID: CURL-SMTP-CRLF-2024 ## CWE-93: Improper Neutralization of CRLF Sequences ##...
## Summary: The Arbitrary Configuration File Inclusion (ACFI) vulnerability was identified in the curl utility via the --config option. This flaw ...
## Summary An attacker can crash or forcefully abort any application that uses libcurl's MQTT support by setting an excessively large value for `CU...
I've provided the detailed description and clear steps previously, but it seems you need the content tailored directly for the submission form's fi...
libcurl's SMTP implementation accepts CR (`\r`) and LF (`\n`) bytes in mailbox address inputs without validation. These control characters are inse...
Hi Hacker ## Impact ## Summary:
HackerOne ## Impact HackerOne
Vulnerability Description The parse_filename function in src/tool_cb_hdr.c does not adequately validate and sanitize filenames extracted from HTTP ...
## Summary: A heap-based buffer overflow vulnerability exists in curl's SOCKS5 proxy handshake implementation when processing HTTP redirects contai...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.