## Summary: The SSL options ISSUERCERT, EC_CURVES and CRLFILE are silently ignored for e.g. the mbedTLS backend, which allows MITM attacks for the ...
## Summary: The cookie parsing code in `lib/cookie.c` contains an integer overflow vulnerability when processing the `Max-Age` attribute of HTTP co...
## Summary: The cookie replacement logic in `lib/cookie.c` contains a use-after-free vulnerability in the `replace_existing()` function. The functi...
Following the recent advisory for **CVE-2025-14524**, I conducted an investigation into how libcurl manages OAuth2 credentials during complex redir...
`libcurl` incorrectly parses IMAP literals (`{size}`) even when they are embedded within quoted strings (e.g., email subjects or headers). This beh...
## Summary The `curl` Gopher protocol handler is vulnerable to command injection through URL-encoded CRLF sequences in the path. This allows an att...
## Summary The Digest authentication implementation in `libcurl` fails to properly escape the `uri` parameter in the `Authorization` header. While ...
## Summary: [directory listing vulnerability is disclosing names and emails and so many other sensitive information, that significantly increases t...
). The API returns struct curl_header objects that internally reference libcurl-owned linked list nodes. When a new request is performed on the sam...
## Summary An unsigned integer underflow exists in libcurl's MQTT publish path. Due to incorrect arithmetic ordering in the size validation logic, ...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.