Recent Advisories

Severity ID Title Vendor Product Date Type
NONE H1:3508500

curl: integer Overflow in MQTT Protocol Handling Allows Bypassing Message Size Limit_H1:3508500

## Summary: A logic error involving an integer overflow (specifically, an unsigned integer underflow) exists in the lib/mqtt.c file within the mqtt...

N/A N/A HACKERONE
NONE H1:3506159

curl: Heap Out-of-Bounds Read in lib/http2.c via Malformed PUSH_PROMISE Headers_H1:3506159

Summary A heap-based out-of-bounds read vulnerability exists in libcurl's HTTP/2 implementation. The on_header callback in lib/http2.c incorrectly ...

N/A N/A HACKERONE
NONE H1:3505557

curl: CRLF Injection in HTTP header values allows arbitrary header injection_H1:3505557

curl allows carriage return `(\r)` and line feed `(\n)` characters inside HTTP header **values**. When attacker-controlled data is used in a header...

N/A N/A HACKERONE
NONE H1:3487952

curl: State Isolation Failure in Multiplexed Connections (Shared Auth Context)_H1:3487952

Vulnerability: State Isolation Failure in Multiplexed Connections (Shared Auth Context) Product: libcurl Affected Versions: v7.43.0 - Current (v8.x...

N/A N/A HACKERONE
NONE H1:3493602

curl: Stack Buffer Overflow in mprintf.c formatting function (fallback path)_H1:3493602

### Summary A stack-based buffer overflow exists in `mprintf.c` within the `out_double()` function. This vulnerability affects builds where `HAVE_S...

N/A N/A HACKERONE
NONE H1:3494098

curl: inconsistently Rejection Logic in file:// URLs with Authority_H1:3494098

curl's `file://` protocol handler inconsistently applies path sanitization. in reject `file://../` as Bad File:// URL" but allows the same travers...

N/A N/A HACKERONE
NONE H1:3488278

curl: MQTT: Missing upper bound on incoming Remaining Length allows server-controlled long wait_H1:3488278

Curl's MQTT implementation accepts any valid Remaining Length advertised by the server without an explicit upper bound (beyond the MQTT spec maximu...

N/A N/A HACKERONE
CRITICAL 9.8 H1:3485826

curl: Alt-Svc bypasses credential leak protection (CVE-2018-1000007)_H1:3485826

## Summary I found a bug where curl's Alt-Svc implementation fails to strip sensitive authentication headers (Authorization and Cookies) when remap...

N/A N/A HACKERONE
HIGH 8.1 H1:3485930

curl: Path Traversal in curl file:// Protocol Handler Allows Unauthorized File Access_H1:3485930

## Summary During my manual review of the file path handling logic in curl's source code, I noticed the absence of proper validation for directory ...

N/A N/A HACKERONE
NONE H1:3483902

curl: PROTOCOL-LEVEL: Persistent UDP Amplification and Cache Poisoning via Alt-Svc Logic Flaw_H1:3483902

## Summary A structural logic flaw in the `libcurl` `Alt-Svc` header parser allows attack attributes (specifically `persist` and `max-age`) to "lea...

N/A N/A HACKERONE