## Summary: A lack of CRLF validation in `Curl_add_custom_headers` at `lib/http.c:1761` allows users to inject arbitrary HTTP headers. This violat...
Control characters slip through during URL handling in curl’s Gopher setup. Though null bytes get blocked by the `REJECT_ZERO` setting, returns and...
Hi **curl Security Team and fellow security researchers**, **Sorry in advance** if this isn’t a traditional security report. I know your time is v...
## Executive Summary **Vulnerability Type:** CWE-190 **Component:** lib/mqtt.c **Function:** mqtt_decode_len **Affected Architectures:** - **...
================================================================================ VULNERABILITY REPORT: HTTP/2 and HTTP/3 Header Injection in curl =...
## Summary curl leaks the Proxy-Authorization header to the origin server after following an HTTP redirect that transitions from a proxied connect...
## Executive Summary A critical security vulnerability has been identified in `libcurl`'s SMTP protocol handler. The vulnerability allows for **SMT...
## Summary A buffer pointer underflow vulnerability exists in curl's telnet protocol handler (`lib/telnet.c`). When processing telnet suboptions i...
## Summary: This report describes a state‑level security invariant violation in libcurl where credential‑ or key‑related state may persist or be re...
## Summary: I have discovered a CRLF injection vulnerability in the IMAP protocol implementation of libcurl. The vulnerability exists because the `...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.