-Infinity
0

Vendor Risk Score

See how haxx compares to other vendors in security performance

View Risk Score →

debian/curlSSH improper host validation

Risk 42
Severity
7.4
EPSS
0.33%
First published (updated )

libcurlsending old referer

Risk 31
Severity
7.5
EPSS
0.40%
First published (updated )

debian/curlexposing HTTP/3 early data

Risk 31
Severity
7.5
EPSS
0.27%
First published (updated )

debian/curlUAF after pause in socket callback

Risk 37
Severity
7.3
EPSS
0.29%
First published (updated )

debian/curlstale proxy password leak

Risk 63
Severity
9.8
EPSS
0.58%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libcurlincomplete mTLS config matching in conn reuse

Risk 32
Severity
7.5
EPSS
0.40%
First published (updated )

debian/curlenv-set cross-proxy Digest auth state leak

Risk 48
Severity
9.1
EPSS
0.44%
First published (updated )

debian/curlpassword leak with netrc and user in URL

Risk 48
Severity
9.1
EPSS
0.38%
First published (updated )

debian/curlSASL double-free

Risk 62
Severity
9.8
EPSS
0.59%
First published (updated )

debian/curltrailing dot domain super cookie

Risk 48
Severity
9.1
EPSS
0.56%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

debian/curlwrong reuse for different services

Risk 40
Severity
6.5
First published (updated )

debian/curlwrong STARTTLS connection reuse

Risk 63
Severity
8.1
First published (updated )

curl curlproto-default skips SSH verification

Risk 46
Severity
7.5
First published (updated )

libcurl libcurlcross-origin Digest auth state leak

Risk 89
Severity
9.8
First published (updated )

curlWS Auto-PONG memory exhaustion

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

libcurlNative CA trust persist

Risk 69
Severity
9.1
First published (updated )

curlQUIC zero-length UDP datagrams busy-loop

Risk 45
Severity
7.5
First published (updated )

libcurl libcurlHTTP/2 stream-dependency tree UAF

Risk 90
Severity
9.8
First published (updated )

curl libcurlcross-proxy Digest auth state leak

Risk 20
Severity
5.3
EPSS
0.08%
First published (updated )

Microsoft azl3 curl 8.11.1-6stale custom cookie host causes cookie leak

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

curl curlOCSP stapling bypass with Apple SecTrust

Risk 20
Severity
5.3
EPSS
0.02%
First published (updated )

curl curlproxy credentials leak over redirect-to proxy

Risk 38
Severity
5.9
First published (updated )

curl libcurlnetrc credential leak with reused proxy connection

Risk 34
Severity
5.3
First published (updated )

curl libcurlwrong reuse of SMB connection

Risk 46
Severity
7.5
First published (updated )

curl libcurlwrong reuse of HTTP Negotiate connection

Risk 48
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft azl3 curl 8.11.1-6connection reuse ignores TLS requirement

Risk 38
Severity
5.9
First published (updated )

redhat/libcurluse after free in SMB connection reuse

Risk 32
Severity
7.5
EPSS
0.04%
First published (updated )

redhat/libcurlwrong proxy connection reuse with credentials

Risk 29
Severity
6.5
EPSS
0.01%
First published (updated )

redhat/curltoken leak with redirect and netrc

Risk 20
Severity
5.3
EPSS
0.02%
First published (updated )

redhat/libcurlbad reuse of HTTP Negotiate connection

Risk 41
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203